Loading HuntDB...

XSS via SVG file

Medium
U
Ubiquiti Inc.
Submitted None
Reported by 0xspade

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Generic
# Hello Ubuquiti, # Details I was able to upload an svg file to [here](https://community.ubnt.com/t5/media/gallerypage/user-id/559584). so i uploaded an SVG file with XSS on its code and if the attacker give the link to his victim he can grab it's victim's cookie. and regarding to the your Upload image svg file it uploaded even it has an error.. # PoC [link](https://community.ubnt.com/t5/image/serverpage/image-id/0i9D3EF39FC6246359/image-size/thumb/is-preview/true?v=1.0&px=100) {F167791} # Fix Dont allow to upload an svg file because attacker can put his payload to a SVG files.

Report Details

Additional information and metadata

State

Closed

Substate

Duplicate

Submitted

Weakness

Cross-site Scripting (XSS) - Generic