Junglewise Threat Intelligence

CVE-2021-23439: file-upload-with-preview cross-site scripting via filename

CVE-2021-23439 · Severity: low · CVSS 3.1 · Published 2021-09-07

Vendors: npm.

Executive brief

file-upload-with-preview is a JavaScript library that provides file upload functionality with preview capabilities on web pages. The vulnerability allows an attacker to inject malicious JavaScript code through a crafted filename; when a user uploads such a file, the code executes in the browser, potentially allowing the attacker to steal session data, modify page content, or perform actions on behalf of the user.

Technical details

This is a Cross-site Scripting (XSS) vulnerability (CWE-79) in the file-upload-with-preview npm package before version 4.2.0. The vulnerable code fails to properly sanitize or encode the uploaded file's name before inserting it into the DOM, allowing malicious JavaScript in the filename to execute when the file preview is displayed. An attacker must trick a user into uploading a specially crafted file (e.g., "image.jpg<img src=x onerror=alert(1)>.jpg"), but no authentication is required. The fix was applied in version 4.2.0, which properly sanitizes filename output.

Affected products

  • John Datserakis file-upload-with-preview before 4.2.0

Timeline

  • 2021-09-07: disclosed
  • 2021-09-05: patched: Fixed in version 4.2.0

References