Security Advisory
CVE-2022-23065
5.4
MEDIUM
Vulnerability Description
In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular users.
Published Date
May 2, 2022
Official Source
NIST NVD Advisory