CVE-2024-28147

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
20/06/2024
Last modified:
01/08/2024

Description

An authenticated user can upload arbitrary files in the upload <br /> function for collection preview images. An attacker may upload an HTML <br /> file that includes malicious JavaScript code which will be executed if a<br /> user visits the direct URL of the collection preview image (Stored <br /> Cross Site Scripting). It is also possible to upload SVG files that <br /> include nested XML entities. Those are parsed when a user visits the <br /> direct URL of the collection preview image, which may be utilized for a <br /> Denial of Service attack.<br /> <br /> This issue affects edu-sharing: