vendor:
CouchCMS
by:
xxcdd
4.3
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: CouchCMS
Affected Version From: 2.2.2001
Affected Version To: 2.2.2001
Patch Exists: NO
Related CWE:
CPE: a:couchcms:couchcms:2.2.1
Platforms Tested: Windows 7
2021
CouchCMS 2.2.1 – XSS via SVG file upload
An issue was discovered in CouchCMS v2.2.1 that allows XSS via an /couch/includes/kcfinder/browse.php SVG upload.
Mitigation:
Sanitize user input and disallow SVG file uploads.