CVE-2023-26771

Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious picture which will trigger the payload when the victim opens the file.
Configurations

No configuration.

History

07 Oct 2024, 19:36

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

07 Oct 2024, 17:48

Type Values Removed Values Added
Summary
  • (es) Taskcafe 0.3.2 es vulnerable a Cross Site Scripting (XSS). Hay una falta de validación en el tipo de archivo cuando se carga una imagen de perfil SVG con un payload XSS. Un atacante autenticado puede aprovechar esta vulnerabilidad cargando una imagen maliciosa que activará el payload cuando la víctima abra el archivo.

04 Oct 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-04 19:15

Updated : 2024-10-07 19:36


NVD link : CVE-2023-26771

Mitre link : CVE-2023-26771

CVE.ORG link : CVE-2023-26771


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')