In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/directus/api/issues/979 | issue tracking exploit third party advisory |
https://github.com/directus/api/projects/42 | third party advisory |