GetmeUK ContentTools Cross-Site Scripting Vulnerability in Image Handler Component

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in GetmeUK ContentTools versions through 1.6.16. The issue arises in the Image Handler component, where the 'onload' attribute can be manipulated to inject malicious JavaScript. This vulnerability can be exploited remotely and requires user interaction.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, upload an image with an 'onload' attribute containing a JavaScript payload to a WYSIWYG editor using GetmeUK ContentTools. Save the changes, and the injected script will execute, demonstrating the cross-site scripting vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.