Junglewise Threat Intelligence

CVE-2021-25967: PYSEC-2021-841 - In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile picture. This allows low p

CVE-2021-25967 · Severity: low · CVSS 3.1 · Published 2021-12-01

Technologies: ckan (PyPI). Vendors: PyPI.

Executive brief

In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile picture. This allows low privileged application users to store malicious scripts in their profile picture. These scripts are executed in a victim’s browser when they open the malicious profile picture

Affected products

  • PyPI ckan

Related threats