In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability. A low privileged attacker can upload a crafted HTML file as a profile avatar, and when an admin or another user opens it, the XSS payload gets triggered.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-27266 In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability. A low privileged attacker can upload a crafted HTML file as a profile avatar, and when an admin or another user opens it, the XSS payload gets triggered.
Fixes

Solution

Update to directus version 9.4.2


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mend

Published:

Updated: 2024-09-16T18:44:02.548Z

Reserved: 2021-12-21T00:00:00

Link: CVE-2022-22117

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-10T16:15:10.120

Modified: 2024-11-21T06:46:13.127

Link: CVE-2022-22117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.