Craft CMS 2.6 - Cross-Site...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Technical Details & Description: ================================ The security risk of the xss vulnerability is estimated as medium with a common vulnerability scoring system count of 3.6. Exploitation of the persistent xss web vulnerability requires a limited editor user account with low privileged (only editing news) and only low user interaction. If attacker upload any file that can use for XSS (HTML, SWF, PHP etc..) it will not accept to uplaod as image. But for images it will stay the same. So if attacker upload SVG with JS content it will work fine and execute JS! The "Content-Type: image/svg+xml; charset=us-ascii" header will make this XSS attack work. Successful exploitation of the XSS vulnerability results in persistent phishing attacks, session hijacking, persistent external redirect to malicious sources and persistent manipulation of affected or connected web module context. Proof of Concept (PoC): ======================= The persistent input validation vulnerability can...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息