PT-2022-18337 · Buttercms · Buttercms

Published

2022-04-12

·

Updated

2022-07-28

·

CVE-2022-27260

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ButterCMS version 1.2.8
Description An arbitrary file upload vulnerability in the file upload component allows attackers to execute arbitrary code via a crafted SVG file.
Recommendations For ButterCMS version 1.2.8, update to a version that fixes the arbitrary file upload vulnerability in the file upload component to prevent attackers from executing arbitrary code via crafted SVG files.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-27260
GHSA-3V5X-QJRP-Q2HQ

Affected Products

Buttercms