PT-2024-34656 · Zusam · Zusam
Ppfeister
·
Published
2024-11-01
·
Updated
2024-11-02
·
CVE-2024-51492
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Zusam versions prior to 0.5.6
Description
The issue allows for unrestricted script execution on image load when specially crafted SVG files are uploaded to the service. This can lead to the theft of a target user's long-lived session token, which remains valid indefinitely unless the user requests a new one. The session token is used interchangeably with the user's static API key on the platform.
Recommendations
For versions prior to 0.5.6, update to version 0.5.6 to fix the cross-site scripting vulnerability. As a temporary workaround, consider restricting the upload of SVG files to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zusam