Impact
The vulnerability allows any user who can change the application logo to upload a crafted SVG file containing embedded JavaScript. When the logo is viewed or opened, the embedded script executes in the victim’s browser context, providing client‑side code execution. The attacker does not gain server‑side privileges and is limited to the scope of the compromised user session.
Affected Systems
MyComplianceOffice MCO. The defect has been confirmed only in version 25.3.3.1; other versions may also be affected, but this has not yet been verified. Vendor outreach attempts were unsuccessful and no public fix has been released.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. The EPSS score of < 1% signifies a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an account with permission to upload or modify the application logo, typically administrators or users with configuration privileges. The impact is limited to client‑side JavaScript execution and does not provide any server‑side access.
OpenCVE Enrichment