PT-2018-10671 · Yootheme · Yootheme Pagekit
Deepin2
+1
·
Published
2018-06-01
·
Updated
2022-05-14
·
CVE-2018-11564
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
YOOtheme Pagekit versions 1.0.13 and earlier
Description
The issue allows a user to upload malicious code via the picture upload feature, specifically by uploading a photo in SVG format. This file is not stripped or filtered by the system. An attacker can create a link on the website pointing to "/storage/poc.svg" which triggers a XSS attack when clicked.
Recommendations
For YOOtheme Pagekit versions 1.0.13 and earlier, consider disabling the picture upload feature, especially for users with elevated privileges, until a fix is available. Restrict access to the "/storage/" directory to minimize the risk of exploitation. Avoid using the picture upload feature in SVG format until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yootheme Pagekit