Impact
The vulnerability allows an authenticated user with media.create permission to upload an SVG file containing malicious script tags without proper sanitization, creating a stored XSS flaw. When any user, including administrators, opens the file from the application, the embedded JavaScript runs in the dashboard context, permitting the attacker to hijack the victim's session and potentially gain full administrative control.
Affected Systems
LaraDashboard versions 0.9.0 to 1.2.2 are affected. The product is provided by the vendor laradashboard under the same name. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path requires the attacker to be authenticated and possess the media.create permission to upload a crafted SVG. Once uploaded, any user who opens the inline file triggers the stored script, enabling session hijacking and possible administrative takeover.
OpenCVE Enrichment