Skip to content

SVG Image Reflected Cross-site Scripting (XSS) vulnerability

Moderate
vladbailescu published GHSA-qcgc-6q86-7x2p Aug 5, 2022

Package

maven core.wcm.components.core (Maven)

Affected versions

< 2.20.8

Patched versions

2.20.8

Description

Impact

Core Components version 2.20.6 (and earlier) suffer from a Reflected Cross-site Scripting (XSS) vulnerability in AdaptiveImageServlet via SVG images. An attacker with author access can upload a special crafted SVG image (including a malicious Javascript) and obtain a link that, when loaded by another authenticated users, will execute the malicious script and gain access to other user's session.

Patches

The issue has been resolved in 2.20.8.

Workarounds

None

References

N/A

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2022-35697

Weaknesses