Description
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.
Remediation
References
https://github.com/payloadcms/payload
https://www.youtube.com/watch?v=6CfhAxA3xdQ
Related Vulnerabilities
CVE-2021-44908 Vulnerability in npm package sails
CVE-2017-12617 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2020-19698 Vulnerability in npm package editor.md
CVE-2019-0199 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2019-10416 Vulnerability in maven package org.jenkins-ci.plugins:violation-comments-to-gitlab