Headline
GHSA-vv3r-fxqp-vr3f: XSS via uploaded gpx file
A malicious content author could upload a GPX file with a Javascript payload. The payload could then be executed by luring a legitimate user to view the file in a browser with support for GPX files. GPX is an XML-based format used to store GPS data.
By default, Silverstripe CMS will no longer allow GPX files to be uploaded to the assets area.
XSS via uploaded gpx file
Moderate severity GitHub Reviewed Published Nov 21, 2022 • Updated Nov 21, 2022
Related news
CVE-2022-38147: CVE-2022-38147 XSS via uploaded gpx file
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).