216.73.217.172

CVE-2024-13141

· Published 05/01/2025 15:15 · Modified 10/01/2025 21:39

Labels: CVE-2024-13141 2025-01-05CVE-2024-13141CWE-79[email protected]

Essential information

Published
05/01/2025 15:15
Modified
10/01/2025 21:39
Author
Creator
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability classified as problematic was found in osuuu LightPicture up to 1.2.2. This vulnerability affects unknown code of the file /api/upload of the component SVG File Upload Handler. The manipulation of the argument file leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
osuuu / lightpicture cpe:2.3:a:osuuu:lightpicture:1.2.0:*:*:*:*:*:*:*
osuuu / lightpicture cpe:2.3:a:osuuu:lightpicture:1.2.1:*:*:*:*:*:*:*
osuuu / lightpicture cpe:2.3:a:osuuu:lightpicture:1.2.2:*:*:*:*:*:*:*

References