PT-2021-21608 · Unknown · Laravel Booking System Booking Core

Published

2021-10-04

·

Updated

2021-10-12

·

CVE-2021-37330

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Laravel Booking System Booking Core version 2.0
Description The issue concerns a Cross Site Scripting (XSS) problem. Specifically, the Avatar upload feature in the My Profile section can be exploited by uploading a malicious SVG file that contains JavaScript. When another user or admin views the profile and clicks to view the avatar, the XSS is triggered.
Recommendations For Laravel Booking System Booking Core version 2.0, consider disabling the Avatar upload feature in the My Profile section until a patch is available to prevent the upload of malicious SVG files. Restrict access to user profiles to minimize the risk of exploitation. Avoid allowing users to upload files that could contain executable code, such as SVG files with embedded JavaScript, until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37330

Affected Products

Laravel Booking System Booking Core