NONE 0.0 NuGet
Stored XSS via SVG File Upload
GHSA-6xmx-85x3-4cv2 · CVE-2023-49279
Published · Modified
Description
Impact
A user with access to the backoffice can upload SVG files that include scripts. If the user can trick another user to load the media directly in a browser, the scripts can be executed.
Workaround
Implement the server side file validation
https://docs.umbraco.com/umbraco-cms/reference/security/serverside-file-validation
or
Serve all media from an different host (e.g cdn) that where umbraco is hosted
Ready to move
Start Securing
Free, no credit card | First findings in minutes