HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the "Forms" feature containing an assets field, or within the control panel which requires authentication.
It has been patched on 3.4.15 and 4.36.0.
{ "nvd_published_at": "2023-11-21T23:15:08Z", "cwe_ids": [ "CWE-79" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-11-22T20:55:07Z" }