Impact
The flaw permits an attacker to upload an SVG file to the /equipmentFile/upload endpoint of zhitan‑ems 1.0.0. When the stored SVG is displayed or processed, malicious script code embedded in the file can run in the victim’s browser. This stored XSS can lead to session hijacking, credential theft, defacement, or other client‑side attacks typical of XSS vulnerabilities, indicating insufficient validation or sanitization of uploaded SVG content.
Affected Systems
The vulnerability exists in version 1.0.0 of the zhitan‑ems management system. No additional product versions are specified, and the vendor is not listed in the CNA data. Administrators should verify whether 1.0.0 is deployed and if the SVG upload capability remains active within their environment.
Risk and Exploitability
An attacker can craft a malicious SVG file and submit it through the open upload endpoint. Once the file is accepted, any user who opens or triggers the SVG will be exposed to the injected script. EPSS information is unavailable and the flaw is not in CISA’s KEV catalog, implying a lower public exploitation probability at present. However, without a specified CVSS score the exact severity cannot be quantified, but stored XSS behaviors demand proactive mitigation.
OpenCVE Enrichment