PT-2025-2027 · Unknown · Osuuu Lightpicture
Jiashenghe
·
Published
2025-01-05
·
Updated
2025-01-10
·
CVE-2024-13141
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
osuuu LightPicture versions 1.2.2 and earlier
Description
A problematic vulnerability was found in osuuu LightPicture, affecting unknown code of the file "/api/upload" of the component SVG File Upload Handler. The manipulation of the
argument file leads to cross-site scripting attacks. These attacks can be initiated remotely.Recommendations
For versions 1.2.2 and earlier, as a temporary workaround, consider disabling the "/api/upload" endpoint until a patch is available. Restrict access to the SVG File Upload Handler component to minimize the risk of exploitation. Avoid using the
argument file in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Osuuu Lightpicture