PT-2022-25291 · WordPress · Svg Support
Marco Wotschka
·
Published
2022-11-16
·
Updated
2022-11-18
·
CVE-2022-4022
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SVG Support plugin for WordPress versions 2.5 through 2.5.1
Description
The SVG Support plugin for WordPress defaults to insecure settings, allowing authenticated attackers with author-level privileges and higher to upload malicious SVG files. These files can contain malicious JavaScript and are not sanitized by the plugin. The embedded JavaScript can be triggered when visiting the image URL, enabling an attacker to execute malicious code in browsers visiting that URL.
Recommendations
For version 2.5, enable sanitization of uploaded images and restrict SVG upload to only administrators.
For version 2.5.1, enable sanitization of uploaded images and restrict SVG upload to only administrators.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Svg Support