PT-2024-21998 · Unknown · Huly Platform

·

CVE-2024-27706

·

Published

2024-04-03

·

Updated

2024-11-01

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Huly Platform version 0.6.202
Description The issue allows attackers to execute arbitrary code via the upload of a crafted SVG file to issues, which is a result of a Cross Site Scripting vulnerability.
Recommendations For Huly Platform version 0.6.202, consider restricting the upload of SVG files to issues until a patch is available. As a temporary workaround, disabling the ability to upload files to issues may help minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-27706

Affected Products

Huly Platform