First published: Tue Dec 14 2021(Updated: )
An issue was discovered in AbanteCart before 1.3.2. Any low-privileged user with file-upload permissions can upload a malicious SVG document that contains an XSS payload.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Abantecart | <1.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42051 is considered to have a medium severity due to the potential for cross-site scripting (XSS) attacks.
To fix CVE-2021-42051, upgrade AbanteCart to version 1.3.2 or later, which patches the vulnerability.
Any low-privileged user in AbanteCart versions prior to 1.3.2 with file-upload permissions is affected by CVE-2021-42051.
CVE-2021-42051 facilitates cross-site scripting (XSS) attacks through the upload of malicious SVG documents.
Yes, CVE-2021-42051 can potentially be exploited remotely by an attacker who has low-privileged file-upload access.