Vulnerability Description
FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating directly to an SVG file URI could execute arbitrary Javascript code decided by an attacker. This Javascript code could include the execution of HTTP web requests to Flarum, or any other web service. This could allow data to be leaked by an authenticated Flarum user, or, possibly, for data to be modified maliciously. This issue has been patched with v1.2.3, which now sanitizes uploaded SVG files. As a workaround, remove the ability for users to upload SVG files through FoF Upload.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Friendsofflarum | Upload | < 1.2.3 |
Related Weaknesses (CWE)
References
- https://github.com/FriendsOfFlarum/upload/issues/68ExploitIssue TrackingThird Party Advisory
- https://github.com/FriendsOfFlarum/upload/pull/318PatchThird Party Advisory
- https://github.com/FriendsOfFlarum/upload/releases/tag/1.2.3PatchThird Party Advisory
- https://github.com/FriendsOfFlarum/upload/security/advisories/GHSA-fm53-mpmp-7qwThird Party Advisory
- https://github.com/FriendsOfFlarum/upload/issues/68ExploitIssue TrackingThird Party Advisory
- https://github.com/FriendsOfFlarum/upload/pull/318PatchThird Party Advisory
- https://github.com/FriendsOfFlarum/upload/releases/tag/1.2.3PatchThird Party Advisory
- https://github.com/FriendsOfFlarum/upload/security/advisories/GHSA-fm53-mpmp-7qwThird Party Advisory
FAQ
What is CVE-2022-30999?
CVE-2022-30999 is a vulnerability with a CVSS score of 8.7 (HIGH). FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+...
How severe is CVE-2022-30999?
CVE-2022-30999 has been rated HIGH with a CVSS base score of 8.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-30999?
Check the references section above for vendor advisories and patch information. Affected products include: Friendsofflarum Upload.