216.73.216.6

CVE-2025-56515

· Published 01/10/2025 16:15 · Modified 02/10/2025 19:11

Labels: CVE-2025-56515 2025-10-01CVE-2025-56515CWE-79[email protected]

Essential information

Published
01/10/2025 16:15
Modified
02/10/2025 19:11
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowing malicious SVG files with embedded foreignObject elements containing iframe tags and JavaScript event handlers (onmouseover) to be uploaded and stored. When rendered, these SVG files execute arbitrary JavaScript, enabling attackers to steal user sessions, cookies, and perform unauthorized actions in the context of users viewing affected profiles.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fiora / fiora chat application cpe:2.3:a:fiora:fiora_chat_application:1.0.0:*:*:*:*:*:*:*

References