Impact
EasyAdminBundle from version 5.0.0 up to 5.0.13 allows FileField and ImageField to accept browser‑executable uploads. The default template at templates/crud/field/file.html.twig links to stored files for inline same‑origin rendering without a download attribute or Content‑Disposition header. When uploads are placed under the public web root, an attacker with access to an affected form can upload HTML via FileField or SVG via ImageField, and JavaScript runs in an authenticated administrator’s browser context when the file is opened from the backend. This stored XSS can expose session or CSRF tokens and facilitate privilege escalation. The flaw is limited to browser‑executable uploads and does not allow execution of server‑side PHP or PHTML code because Symfony’s extension filtering prevents those types.
Affected Systems
The affected product is EasyAdminBundle from EasyCorp, with insecure inline rendering in FileField and ImageField templates in versions 5.0.0 to 5.0.13. This impacts Symfony applications that use the default templates and host uploaded files in the public web root.
Risk and Exploitability
The CVSS score of 7.6 indicates a high‑severity risk. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a moderate privilege gap: the attacker must have the ability to submit files to the vulnerable form and a separate authenticated administrator must later view the file. Once satisfied, the attacker can then execute malicious JavaScript in the administrator’s context, potentially facilitating further attacks. While the likelihood of exploitation is not quantified, the high CVSS and nature of the flaw imply that it is a significant concern for applications exposed to untrusted file uploads.
OpenCVE Enrichment
Github GHSA