CVE-2022-27263: Malicious File Upload
Published Apr 12, 2022
·Updated
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.
Affected Software
1 affected component
Strapi Strapi=4.1.5
Event History
Apr 12, 2022
CVE Published
via MITRE·04:29 PM
Data Sourced
via MITRE·04:29 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Strapi vulnerability?
The vulnerability ID of this Strapi vulnerability is CVE-2022-27263.
2
What is the severity level of CVE-2022-27263?
CVE-2022-27263 has a severity level of critical (9.8).
3
How does CVE-2022-27263 affect the software?
CVE-2022-27263 affects Strapi v4.1.5, allowing attackers to execute arbitrary code via a crafted file.
4
Are there any fixes available for CVE-2022-27263?
At the moment, there are no official fixes available for CVE-2022-27263. It is recommended to update to a patched version or apply any available mitigation steps.
5
Where can I find more information about CVE-2022-27263?
You can find more information about CVE-2022-27263 on the official Strapi GitHub repository and on the provided YouTube video link.