Junglewise Threat Intelligence

CVE-2022-27260: ButterCMS unrestricted file upload in file upload component

CVE-2022-27260 · Severity: low · CVSS 3.1 · Published 2022-04-13

Vendors: npm.

Executive brief

ButterCMS, a content management system used to power websites and blogs, contains a security flaw in its file upload feature. An attacker can upload a specially crafted image file (SVG) to take control of the system and execute unauthorized commands. This could lead to a total compromise of the website, including the theft of sensitive data or service disruption.

Technical details

An arbitrary file upload vulnerability (CWE-434) exists in the file upload component of ButterCMS v1.2.8. The system fails to properly validate or sanitize uploaded files, specifically allowing the upload of malicious Scalable Vector Graphics (SVG) files. A remote, unauthenticated attacker can exploit this by uploading a crafted SVG file containing malicious scripts or code. Successful exploitation allows for arbitrary code execution on the server, potentially leading to full system compromise. Public exploits have been documented in the wild.

Affected products

  • ButterCMS ButterCMS 1.2.8

Timeline

  • 2022-04-12: advisory: NVD published CVE-2022-27260
  • 2022-04-13: disclosed: GHSA-3v5x-qjrp-q2hq published

References