U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-28147

Change History

New CVE Received by NIST 6/20/2024 7:15:55 AM

Action Type Old Value New Value
Added CWE

								
							
							
						
SEC Consult Vulnerability Lab CWE-434
Added Description

								
							
							
						
An authenticated user can upload arbitrary files in the upload 
function for collection preview images. An attacker may upload an HTML 
file that includes malicious JavaScript code which will be executed if a
 user visits the direct URL of the collection preview image (Stored 
Cross Site Scripting). It is also possible to upload SVG files that 
include nested XML entities. Those are parsed when a user visits the 
direct URL of the collection preview image, which may be utilized for a 
Denial of Service attack.

This issue affects edu-sharing: <8.0.8-RC2, <8.1.4-RC0, <9.0.0-RC19.
Added Reference

								
							
							
						
SEC Consult Vulnerability Lab https://r.sec-consult.com/metaventis [No types assigned]