Stored XSS Vulnerability in Firefly III Photo Management Tool
CVE-2019-13647

5.4MEDIUM

Key Information:

Vendor
CVE Published:
18 July 2019

What is CVE-2019-13647?

Firefly III versions prior to 4.7.17.3 contain a vulnerability that permits the execution of stored cross-site scripting (XSS) attacks. This issue arises from insufficient filtration of user-supplied data, specifically affecting image file content. When attachments are viewed, malicious JavaScript executed by an attacker could compromise user integrity. Importantly, an attacker must possess the same access rights as the victim’s account to exploit this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.