PT-2022-15254 · Directus · Directus
Published
2022-01-10
·
Updated
2022-01-14
·
CVE-2022-22117
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Directus versions 9.0.0-alpha.4 through 9.4.1
Description
The issue allows for unrestricted file upload of .html files in the media upload functionality, leading to a Cross-Site Scripting vulnerability. A low-privileged attacker can upload a crafted HTML file, such as a profile avatar, and when an admin or another user opens it, the XSS payload gets triggered.
Recommendations
For versions 9.0.0-alpha.4 through 9.4.1, consider restricting the media upload functionality to prevent the upload of .html files until a patch is available. As a temporary workaround, avoid using the media upload feature for uploading profile avatars or other HTML files.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Directus