Webedition CMS Stored Cross-Site Scripting Vulnerability via SVG Upload

Vulnerability

A stored cross-site scripting vulnerability has been identified in Webedition CMS version 2.9.8.8. This vulnerability allows authenticated users to upload malicious SVG files containing embedded JavaScript. The crafted SVG files can be uploaded through the media upload feature, enabling attackers to inject and execute arbitrary scripts when the files are viewed by other users.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected SVG file.

Reproduction

To reproduce this vulnerability, log into an account on Webedition CMS v2.9.8.8. Navigate to the media upload section and select the option to upload an image. Upload a malicious SVG file that contains JavaScript, such as a script that triggers an alert with the document's location. Once the file is uploaded, the injected script will execute when the SVG file is viewed by other users.

Added: Dec 15, 2025, 9:45 PM
Updated: Dec 15, 2025, 10:24 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.0
exploitability
6.5
remediation
0.0
relevance
1.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.