Impact
A flaw in the media-service.server.ts file of SveltyCMS allows an attacker to execute arbitrary JavaScript in the victim’s browser by uploading a crafted SVG file. The vulnerability is a classic reflected or stored XSS (CWE‑79) and is also associated with code injection weaknesses in the SVG handling logic (CWE‑94).
Affected Systems
SveltyCMS version 0.0.6 is affected; the issue resides in the SVG media upload component located at src/utils/media/media-service.server.ts.
Risk and Exploitability
The CVSS score of 5.1 classifies the problem as moderate severity, while the EPSS score of less than 1 % indicates a very low, but non‑zero, likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack can be triggered remotely by submitting a malicious SVG file to the media upload endpoint, leveraging the lack of proper sanitisation and encoding of SVG input.
OpenCVE Enrichment