Description
In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privileged attacker can inject arbitrary javascript code which will be executed in a victim’s browser when they open the image URL.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to directus version 9.4.2
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-27265 | In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privileged attacker can inject arbitrary javascript code which will be executed in a victim’s browser when they open the image URL. |
References
History
No history.
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2024-09-17T03:13:41.409Z
Reserved: 2021-12-21T00:00:00.000Z
Link: CVE-2022-22116
No data.
Status : Modified
Published: 2022-01-10T16:15:10.057
Modified: 2024-11-21T06:46:12.983
Link: CVE-2022-22116
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD