Cross-site Scripting via uploaded SVG
Package
Affected versions
>= 2.0.0-RC1, < 2.5.21
>= 2.6.0-RC1, < 2.6.5
Patched versions
2.5.21
2.6.5
Description
Published by the National Vulnerability Database
Oct 3, 2024
Published to the GitHub Advisory Database
Oct 3, 2024
Reviewed
Oct 3, 2024
Last updated
Oct 18, 2024
In Sulu v2.0.0 through v2.6.4 are vulnerable against XSS whereas a low privileged user with an access to the “Media” section can upload an SVG file with a malicious payload. Once uploaded and accessed, the malicious javascript will be executed on the victims’ (other users including admins) browsers.
References