Stored XSS Vulnerability in SPIP 4.0.0 via Malicious SVG File

Stored XSS Vulnerability in SPIP 4.0.0 via Malicious SVG File

CVE-2021-44118 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).

Learn more about our Web App Pen Testing.