A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies.
The below link is a private YouTube video for PoC.
https://youtu.be/5j8owD0--1A
The stored XSS can lead to session hijacking and privilege escalation, effectively bypassing any CSRF protections in place.
| Score | Percentile |
|---|---|
| 0.14% | 33.96% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 7.3 | 3.1 | — |
|
| 6.9 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-cgr4-c233-h733 ↗ |
| CVE | CVE-2024-52305 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| composer | unopim/unopim | < 0.1.5 | 0.1.5 | — |