Cross-site Scripting via uploaded SVG
Package
Affected versions
>= 2.0.0-RC1, < 2.5.21
      >= 2.6.0-RC1, < 2.6.5
  Patched versions
2.5.21
      2.6.5
  Description
        Published by the National Vulnerability Database
      Oct 3, 2024 
    
  
        Published to the GitHub Advisory Database
      Oct 3, 2024 
    
  
        Reviewed
      Oct 3, 2024 
    
  
        Last updated
      Oct 18, 2024 
    
  
In Sulu v2.0.0 through v2.6.4 are vulnerable against XSS whereas a low privileged user with an access to the “Media” section can upload an SVG file with a malicious payload. Once uploaded and accessed, the malicious javascript will be executed on the victims’ (other users including admins) browsers.
References