Skip to content

Stored XSS injection when viewing uploaded files

High
devGregA published GHSA-f82x-m585-gj24 Jan 23, 2022

Package

Defect Dojo (GitHub)

Affected versions

< 2.6.0

Patched versions

2.6.0

Description

Impact

Files can be uploaded for Engagements, Tests and Findings. If such a file contains an XSS injection, this injection is executed when viewing the file.

Patches

The issue has been patched with release 2.6.0. Now the the HTTP header Content-Disposition: attachment is used and the file gets downloaded as an attachment rather than viewing it directly in th browser.

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

No known CVE

Weaknesses

Credits