Impact
Laravel‑Mediable before version 7.0.0 contains a stored cross‑site scripting flaw (CWE‑79) that allows attackers to upload SVG files with embedded JavaScript. The malicious content can be placed in onload event handlers, victim opens or previews the SVG, the code executes with full DOM privileges, enabling session cookie theft, CSRF token capture, and account takeover.
Affected Systems
The vulnerable package is Laravel‑Mediable from the vendor plank. All releases older than 7.0.0 are affected and no specific build or patch level is enumerated in the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog, suggesting limited documented exploitation. The likely attack vector is remote via the public web interface, using file upload functionality, and it can be triggered by both authenticated and unauthenticated users. An attacker who successfully uploads a malicious SVG can target any user who subsequently opens or previews the file, resulting in persistent client‑side compromise with full DOM access.
OpenCVE Enrichment