Stored Cross-Site Scripting (XSS) vulnerability in i2A...
Moderate severity
Unreviewed
Published
May 26, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
May 26, 2025
Published to the GitHub Advisory Database
May 26, 2025
Stored Cross-Site Scripting (XSS) vulnerability in i2A-Cronos version 23.02.01.17, from i2A. It allows an authenticated attacker to upload a malicious SVG image into the user's personal space in /CronosWeb/Modules/Persons/PersonalDocuments/PersonalDocuments.
There is no reported fix at this time.
References