First published: Sun Jan 05 2025(Updated: )
A vulnerability classified as problematic was found in osuuu LightPicture up to 1.2.2. This vulnerability affects unknown code of the file /api/upload of the component SVG File Upload Handler. The manipulation of the argument file leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
osuuu LightPicture | =1.2.0 | |
osuuu LightPicture | =1.2.1 | |
osuuu LightPicture | =1.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13141 is classified as problematic due to its potential for exploitation through cross-site scripting.
To fix CVE-2024-13141, update osuuu LightPicture to a version that addresses the SVG File Upload Handler vulnerability.
CVE-2024-13141 affects osuuu LightPicture versions 1.2.0, 1.2.1, and 1.2.2.
CVE-2024-13141 is a Cross-Site Scripting (XSS) vulnerability that can be exploited through the upload of SVG files.
CVE-2024-13141 exists in the /api/upload endpoint of the SVG File Upload Handler in the osuuu LightPicture application.