Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://huntr.dev/bounties/4d97f665-c9f1-4c38-b774-692255a7c44c | third party advisory exploit |
https://github.com/publify/publify/commit/0fb6b027fbaf17f6a6551f2148482a03eac12927 | third party advisory patch |