Description
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.
Remediation
References
https://github.com/payloadcms/payload
https://www.youtube.com/watch?v=6CfhAxA3xdQ
Related Vulnerabilities
CVE-2019-10424 Vulnerability in maven package com.technicolor:eloyente
CVE-2020-24025 Vulnerability in npm package node-sass
CVE-2020-28455 Vulnerability in npm package markdown-it-toc
CVE-2022-41853 Vulnerability in maven package org.hsqldb:hsqldb
CVE-2022-39299 Vulnerability in npm package @node-saml/node-saml