vendor:
Magnolia CMS
by:
Giulio Garzia 'Ozozuz'
6.1
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Magnolia CMS
Affected Version From: 6.2.19
Affected Version To: 6.2.19
Patch Exists: YES
Related CWE: CVE-2022-33098
CPE: a:magnolia-cms:magnolia_cms:6.2.19
Platforms Tested: Linux, Windows, Docker
2022
Magnolia CMS 6.2.19 – Stored Cross-Site Scripting (XSS)
Malicious user with the permissions to upload profile picture for a contact, can upload an SVG file containing malicious JavaScript code that will be executed by anyone opening the malicious resource.
Mitigation:
Ensure that user input is properly sanitized and validated before being stored and displayed.