CVE Feed

    Dashboard / CVE / CVE-2024-52597

    CVE-2024-52597

    2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Versions prior to 5.4.1 are vulnerable to stored cross-site scripting due to improper headers in direct access to uploaded SVGs. The application allows uploading images in several places. One of the accepted types of image is SVG, which allows JS scripting. Therefore, by uploading a malicious SVG which contains JS code, an attacker which is able to drive a victim to the uploaded image could compromise that victim's session and access to their tokens. Version 5.4.1 contains a patch for the issue.

    Published:Nov 20, 2024
    Last Modified:Aug 4, 2025
    EPS:Nov 20, 2024
    EPSS Score:0.0022
    CVSS Score:6.1

    Affected Products

    Vendor
    2fauth
    Product
    2fauth
    Vendor
    Bubka
    Product
    2fauth

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High