A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed by other backend users, it allows authenticated attackers to execute arbitrary JavaScript in the context of other backend users' browsers, potentially leading to the theft of sensitive tokens.
History

Thu, 24 Apr 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ujcms
Ujcms ujcms
CPEs cpe:2.3:a:ujcms:ujcms:9.6.3:*:*:*:*:*:*:*
Vendors & Products Ujcms
Ujcms ujcms

Tue, 17 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Dec 2024 22:30:00 +0000

Type Values Removed Values Added
Description A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed by other backend users, it allows authenticated attackers to execute arbitrary JavaScript in the context of other backend users' browsers, potentially leading to the theft of sensitive tokens.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-12-16T00:00:00

Updated: 2024-12-17T16:56:32.250Z

Reserved: 2024-12-06T00:00:00

Link: CVE-2024-55451

cve-icon Vulnrichment

Updated: 2024-12-17T16:56:13.014Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-16T23:15:06.710

Modified: 2025-04-24T15:26:43.720

Link: CVE-2024-55451

cve-icon Redhat

No data.