Cross-Site Scripting Vulnerability in PageKit CMS by PageKit
CVE-2021-32245

5.4MEDIUM

Key Information:

Vendor

Pagekit

Status
Vendor
CVE Published:
16 June 2021

What is CVE-2021-32245?

In PageKit version 1.0.18, a vulnerability allows users to upload SVG files without proper security measures. These SVG files can include malicious scripts which are not filtered upon upload. Users can create links on the website that reference the uploaded SVG files. When other users click these links, it can lead to exploitation through XSS attacks, potentially compromising user sessions and sensitive data.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.