Arbitrary File Upload Vulnerability in PayloadCMS by Payload
CVE-2022-27952
9.8CRITICAL
What is CVE-2022-27952?
An arbitrary file upload vulnerability exists in the file upload module of PayloadCMS version 0.15.0. This flaw enables an attacker to upload a specially crafted SVG file that can be used to execute arbitrary code on the server. The ability to execute arbitrary code poses a significant risk as it could lead to full system compromise, data breaches, and unauthorized access to sensitive information.
