Insecure file upload In payload
Description
Unrestricted Upload of File with Dangerous Type in Payload An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 0.15.1 |
Aliases
1. 2. 3. 4.
References
1.