PT-2022-20445 · Unknown · Fof Upload
Safwat Refaat
·
Published
2022-05-25
·
Updated
2022-06-10
·
CVE-2022-30999
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FoF Upload versions prior to 1.2.3
Description
The issue allows arbitrary Javascript code execution when navigating directly to an SVG file URI, potentially leading to data leakage or malicious modification by an authenticated Flarum user. This is possible if FoF Upload is configured to allow the uploading of SVG files (
image/svg+xml). The executed Javascript code could include HTTP web requests to Flarum or other web services.Recommendations
For FoF Upload versions prior to 1.2.3, upgrade to version 1.2.3, which sanitizes uploaded SVG files, or remove the ability for users to upload SVG files through FoF Upload as a temporary workaround.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fof Upload