vendor:
Projeqtor
by:
Oscar Gutierrez (m4xp0w3r)
7.5
CVSS
HIGH
Stored Cross Site Scripting (XSS)
79
CWE
Product Name: Projeqtor
Affected Version From: 9.3.2001
Affected Version To: 9.3.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Ubuntu, LAAMP
2021
Projeqtor v9.3.1 – Stored Cross Site Scripting (XSS)
Projeqtor version 9.3.1 suffers from a stored XSS vulnerability via SVG file upload. A low level user can upload svg images that contain malicious Javascript. In this way an attacker can escalate privileges and upload a malicious plugin which results in arbitrary code execution in the server hosting the application.
Mitigation:
Update to the latest version of Projeqtor or apply a security patch provided by the vendor. Avoid uploading untrusted SVG files.