Логотип exploitDog
bind:CVE-2022-24749
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-24749

Количество 2

Количество 2

nvd логотип

CVE-2022-24749

почти 4 года назад

Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a XSS attack, the file itself has to be open in a new card or loaded outside of the IMG tag. The problem applies both to the files opened on the admin panel and shop pages. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. As a workaround, require a library that adds on-upload file sanitization and overwrite the service before writing the file to the filesystem. The GitHub Security Advisory contains more specific information about the workaround.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4qrp-27r3-66fj

почти 4 года назад

Improper sanitize of SVG files during content upload ('Cross-site Scripting') in sylius/sylius

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-24749

Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a XSS attack, the file itself has to be open in a new card or loaded outside of the IMG tag. The problem applies both to the files opened on the admin panel and shop pages. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. As a workaround, require a library that adds on-upload file sanitization and overwrite the service before writing the file to the filesystem. The GitHub Security Advisory contains more specific information about the workaround.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-4qrp-27r3-66fj

Improper sanitize of SVG files during content upload ('Cross-site Scripting') in sylius/sylius

CVSS3: 6.1
0%
Низкий
почти 4 года назад

Уязвимостей на страницу