Cross-Site Scripting Vulnerability in PageKit CMS by PageKit
CVE-2021-32245
5.4MEDIUM
What is CVE-2021-32245?
In PageKit version 1.0.18, a vulnerability allows users to upload SVG files without proper security measures. These SVG files can include malicious scripts which are not filtered upon upload. Users can create links on the website that reference the uploaded SVG files. When other users click these links, it can lead to exploitation through XSS attacks, potentially compromising user sessions and sensitive data.
