Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-28147

Опубликовано: 20 июн. 2024
Источник: nvd
CVSS3: 7.4
EPSS Низкий

Описание

An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may upload an HTML file that includes malicious JavaScript code which will be executed if a user visits the direct URL of the collection preview image (Stored Cross Site Scripting). It is also possible to upload SVG files that include nested XML entities. Those are parsed when a user visits the direct URL of the collection preview image, which may be utilized for a Denial of Service attack.

This issue affects edu-sharing: <8.0.8-RC2, <8.1.4-RC0, <9.0.0-RC19.

EPSS

Процентиль: 57%
0.0035
Низкий

7.4 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.4
github
больше 1 года назад

An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may upload an HTML file that includes malicious JavaScript code which will be executed if a user visits the direct URL of the collection preview image (Stored Cross Site Scripting). It is also possible to upload SVG files that include nested XML entities. Those are parsed when a user visits the direct URL of the collection preview image, which may be utilized for a Denial of Service attack. This issue affects edu-sharing: <8.0.8-RC2, <8.1.4-RC0, <9.0.0-RC19.

CVSS3: 5.5
fstec
почти 2 года назад

Уязвимость компонента Collection Preview системы управления платформами электронного обучения edu-sharing, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 57%
0.0035
Низкий

7.4 High

CVSS3

Дефекты

CWE-434