PT-2021-24029 · Uipath · Uipath App Studio
Published
2021-12-14
·
Updated
2021-12-20
·
CVE-2021-44043
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
UiPath App Studio version 21.4.4
Description:
An issue was discovered in the file-upload functionality for uploading icons when attempting to create new Apps, allowing for a persistent XSS vulnerability. An attacker with minimal privileges can build their own App and upload a malicious file containing an XSS payload by uploading an arbitrary file and modifying the
MIME type in a subsequent HTTP request. This enables the file to be stored and retrieved from the server by other users in the same organization.Recommendations:
For UiPath App Studio version 21.4.4, consider disabling the file-upload functionality for uploading icons until a patch is available to prevent exploitation of the persistent XSS vulnerability. Restrict access to the affected functionality to minimize the risk of exploitation. Avoid using the file-upload feature for uploading icons in the affected version until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uipath App Studio