CVE-2022-38147

MEDIUM5.4EPSS 0.32%

XSS via uploaded gpx file

Published: 11/21/2022Modified: 2/20/2024
Also known as:GHSA-vv3r-fxqp-vr3f

Description

A malicious content author could upload a GPX file with a Javascript payload. The payload could then be executed by luring a legitimate user to view the file in a browser with support for GPX files. GPX is an XML-based format used to store GPS data. By default, Silverstripe CMS will no longer allow GPX files to be uploaded to the assets area.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (6)