GHSA-3v5x-qjrp-q2hq

Suggest an improvement
Source
https://github.com/advisories/GHSA-3v5x-qjrp-q2hq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-3v5x-qjrp-q2hq/GHSA-3v5x-qjrp-q2hq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3v5x-qjrp-q2hq
Aliases
  • CVE-2022-27260
Published
2022-04-13T00:00:24Z
Modified
2023-11-08T04:08:57.989160Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Unrestricted Upload of File with Dangerous Type in ButterCMS
Details

An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.

Database specific
{
    "nvd_published_at": "2022-04-12T17:15:00Z",
    "cwe_ids": [
        "CWE-434"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2022-04-22T21:02:44Z"
}
References

Affected packages

npm / buttercms

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.2.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-3v5x-qjrp-q2hq/GHSA-3v5x-qjrp-q2hq.json"