Impact
The vulnerability allows administrators to upload files with a Content‑Type header supplied only by the client. An attacker can embed malicious JavaScript in SVG or HTML files, which will execute in the application origin when any user accesses the uploaded file. This can lead to session hijacking, data theft, and further exploitation of the application. The weakness is identified as CWE‑434.
Affected Systems
lin‑snow Ech0 versions prior to 4.4.3 are affected. The flaw resides in the file upload endpoint used by administrators to store SVG or HTML files.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score is not available, suggesting no current evidence of exploitation. The flaw is not listed in CISA KEV. Because an attacker must have administrative privileges to upload the malicious file, the attack vector is an authenticated, remote file‑upload scenario. Once an SVG or HTML file is uploaded, any subsequent user who accesses the file will have client‑side code executed, enabling session hijacking and data exfiltration. The risk is therefore moderate but can be high if admin credentials are compromised.
OpenCVE Enrichment