Security Advisory

CVE-2022-23065

5.4
MEDIUM

Vulnerability Description

In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular users.
Published Date May 2, 2022
Official Source NIST NVD Advisory