Impact
The flaw exists because SQLBot accepts SVG files uploaded by an authenticated user without sanitizing them, stores the file, and later serves it inline from the same origin. When an attacker uploads a crafted SVG containing malicious JavaScript, any subsequent user who views the logo has that JavaScript executed with the victim’s session privileges. This allows the attacker to read confidential data, manipulate the application, or perform arbitrary actions with the victim’s rights.
Affected Systems
SQLBot by DataEase, versions prior to 1.9.0, are affected. The flaw is present in the assistant UI logo upload API /api/v1/system/assistant/ui and is remedied in release 1.9.0; older installations remain vulnerable until upgraded.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score of less than 1 % shows a low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. The attack requires an authenticated session with permission to upload the SVG logo, meaning an attacker must first compromise or obtain credentials for a user who has that privilege. If successful, the stored XSS can be triggered by any other logged‑in user who views the image, allowing an attacker to execute arbitrary scripts in their browser context.
OpenCVE Enrichment