GHSA-qcgc-6q86-7x2p
MODERATECVE-2022-35697Core Components version 2.20.6 (and earlier) suffer from a reflected cross-site scripting (XSS) vulnerability in AdaptiveImageServlet via SVG images. An attacker with author access can upload a special crafted SVG image (including a malicious Javascript) and obtain a link that, when loaded by another authenticated users, will execute the malicious script and gain access to other user's session. Th
- Affected
- < 2.20.8
- Fixed in
- 2.20.8
- Weakness
- CWE-79
- Published
- 2022-08-11
- Source
- github