File Upload Vulnerabilities, Explained: From an Avatar Field to a Web Shell
An upload form that trusts the filename, the declared Content-Type or a file's first bytes can place a server-side script or a scripted SVG on your own origin. Here is how upload validation fails, how to test it safely, and how to build a handler that holds.