HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the "Forms" feature containing an assets field, or within the control panel which requires authentication.
It has been patched on 3.4.15 and 4.36.0.
{
"nvd_published_at": "2023-11-21T23:15:08Z",
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed_at": "2023-11-22T20:55:07Z",
"github_reviewed": true
}