GHSA-6xmx-85x3-4cv2
Dashboard / Vulnerabilities / GHSA-6xmx-85x3-4cv2
Summary: Stored XSS via SVG File Upload
Details: #### Impact A user with access to the backoffice can upload SVG files that include scripts. If the user can trick another user to load the media directly in a browser, the scripts can be executed. #### Workaround Implement the server side file validation https://docs.umbraco.com/umbraco-cms/reference/security/serverside-file-validation or Serve all media from an different host (e.g cdn) that where umbraco is hosted
References: https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-6xmx-85x3-4cv2, https://nvd.nist.gov/vuln/detail/CVE-2023-49279, https://docs.umbraco.com/umbraco-cms/reference/security/serverside-file-validation, https://github.com/umbraco/Umbraco-CMS
Affected packages
Package
Name: Umbraco.CMS
Purl: pkg:nuget/Umbraco.CMS
Affected ranges
Type: ECOSYSTEM
Events:
