PT-2025-2027 · Unknown · Osuuu Lightpicture

Jiashenghe

·

Published

2025-01-05

·

Updated

2025-01-10

·

CVE-2024-13141

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions osuuu LightPicture versions 1.2.2 and earlier
Description A problematic vulnerability was found in osuuu LightPicture, affecting unknown code of the file "/api/upload" of the component SVG File Upload Handler. The manipulation of the argument file leads to cross-site scripting attacks. These attacks can be initiated remotely.
Recommendations For versions 1.2.2 and earlier, as a temporary workaround, consider disabling the "/api/upload" endpoint until a patch is available. Restrict access to the SVG File Upload Handler component to minimize the risk of exploitation. Avoid using the argument file in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-13141

Affected Products

Osuuu Lightpicture