Lucene search

K
wpexploitDmitrii IgnatyevWPEX-ID:7C39F3B5-D407-4EB0-AA34-B498FE196C55
HistoryJun 06, 2024 - 12:00 a.m.

H5P < 1.15.8 - Contributor+ Stored XSS

2024-06-0600:00:00
Dmitrii Ignatyev
11
h5p
contributor+
stored xss
exploit
june 20 2024
update

6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Description The plugin does not validate uploads which could allow a Contributors and above to update malicious SVG files, leading to Stored Cross-Site Scripting issues

1. Upload an H5P archive containing a malicious SVG file w/an XSS
2. Example: https://drive.google.com/file/d/1DNZmv-at_HPtDeYr8ExjRrekHSUOaGzh/view?usp=sharing
3. Once the upload is finished, users will be able to access the malicious SVG directly, triggering an XSS

6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Related for WPEX-ID:7C39F3B5-D407-4EB0-AA34-B498FE196C55