PT-2021-21608 · Unknown · Laravel Booking System Booking Core
Published
2021-10-04
·
Updated
2021-10-12
·
CVE-2021-37330
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Laravel Booking System Booking Core version 2.0
Description
The issue concerns a Cross Site Scripting (XSS) problem. Specifically, the Avatar upload feature in the My Profile section can be exploited by uploading a malicious SVG file that contains JavaScript. When another user or admin views the profile and clicks to view the avatar, the XSS is triggered.
Recommendations
For Laravel Booking System Booking Core version 2.0, consider disabling the Avatar upload feature in the My Profile section until a patch is available to prevent the upload of malicious SVG files. Restrict access to user profiles to minimize the risk of exploitation. Avoid allowing users to upload files that could contain executable code, such as SVG files with embedded JavaScript, until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Laravel Booking System Booking Core