PT-2024-36519 · Ujcms · Ujcms

Published

2024-12-16

·

Updated

2024-12-17

·

CVE-2024-55451

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions UJCMS version 9.6.3
Description A Stored Cross-Site Scripting (XSS) issue exists in the authenticated SVG file upload and viewing functionality. This arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed by other backend users, it allows authenticated attackers to execute arbitrary JavaScript in the context of other backend users' browsers, potentially leading to the theft of sensitive tokens.
Recommendations For UJCMS version 9.6.3, as a temporary workaround, consider disabling the SVG file upload functionality until a patch is available. Restrict access to the affected functionality to minimize the risk of exploitation. Avoid using the vulnerable SVG upload feature in the backend until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-55451

Affected Products

Ujcms