icret EasyImages Cross-Site Scripting Vulnerability in SVG Image Handler

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in icret EasyImages versions through 2.8.6. The issue resides in the SVG Image Handler component, specifically within the '/app/upload.php' file. The vulnerability is triggered by manipulating the 'file' argument, allowing remote attackers to execute scripts that could be harmful to users.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, upload a crafted SVG file through the application's upload feature. The file should contain a payload that exploits the XSS vulnerability, such as a script injection or an event handler that triggers a script execution. Once uploaded, access the file through the application to verify the execution of the injected script.

Added: Nov 19, 2025, 10:17 PM
Updated: Nov 19, 2025, 10:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.8
remediation
0.0
relevance
1.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.