vendor:
Pagekit
by:
DEEPIN2
8.8
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Pagekit
Affected Version From: < 1.0.13
Affected Version To: < 1.0.13
Patch Exists: YES
Related CWE: 2018-11564
CPE: a:pagekit:pagekit
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Pagekit < 1.0.13 - Cross-Site Scripting Code Generator
This exploit allows an attacker to inject malicious code into a vulnerable Pagekit version < 1.0.13. The code generator creates a malicious SVG file which contains a script tag with the malicious code. The malicious code is then executed when the SVG file is opened.
Mitigation:
Upgrade to the latest version of Pagekit, 1.0.13 or later.