CVE-2022-30999 is a cross-site scripting (XSS) vulnerability affecting FriendsofFlarum (FoF) Upload versions prior to 1.2.3. If configured to allow SVG file uploads, an attacker can embed arbitrary JavaScript code within an SVG file. Navigating directly to this SVG file URI could execute the attacker's script, potentially leading to data leakage or malicious data modification. The vulnerability has a CVSS score of 5.4 (Medium), indicating a network attack vector, low attack complexity, and requiring user interaction. It could result in limited confidentiality and integrity impacts. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE. A patch is available in FoF Upload v1.2.3, and a workaround involves disabling SVG file uploads.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.3CPE matchmatch criteria | cpe:2.3:a:friendsofflarum:upload:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.