vendor:
Ulicms
by:
Mirabbas Agalarov
7.4
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Ulicms
Affected Version From: 2023.1-sniffing-vicuna
Affected Version To: 2023.1-sniffing-vicuna
Patch Exists: NO
Related CWE:
CPE: a:ulicms:ulicms:2023.1-sniffing-vicuna
Platforms Tested: Linux
2023
Ulicms-2023.1 sniffing-vicuna – Stored Cross-Site Scripting (XSS)
Ulicms is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability. An attacker can upload a malicious SVG file containing a malicious JavaScript code which will be executed when the SVG file is accessed. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Mitigation:
To mitigate this vulnerability, the application should validate the uploaded files and should not allow the upload of malicious files.