CVE-2024-28147
Severity CVSS v4.0:
Pending analysis
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
20/06/2024
Last modified:
01/08/2024
Description
An authenticated user can upload arbitrary files in the upload <br />
function for collection preview images. An attacker may upload an HTML <br />
file that includes malicious JavaScript code which will be executed if a<br />
user visits the direct URL of the collection preview image (Stored <br />
Cross Site Scripting). It is also possible to upload SVG files that <br />
include nested XML entities. Those are parsed when a user visits the <br />
direct URL of the collection preview image, which may be utilized for a <br />
Denial of Service attack.<br />
<br />
This issue affects edu-sharing:
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH



