Description
In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular users.
No analysis available yet.
Remediation
Vendor Solution
Upgrade version to 1.5.2 or higher
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28173 | In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular users. |
References
History
No history.
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2024-09-16T17:03:44.763Z
Reserved: 2022-01-10T00:00:00.000Z
Link: CVE-2022-23065
No data.
Status : Modified
Published: 2022-05-02T13:15:08.247
Modified: 2024-11-21T06:47:54.950
Link: CVE-2022-23065
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD