Slink Stored Cross-Site Scripting Vulnerability
Vulnerability
A stored cross-site scripting vulnerability has been identified in Slink version 1.4.9. This issue allows for the execution of embedded JavaScript in uploaded SVG files. The vulnerability affects both authenticated and unauthenticated users. When a crafted SVG is uploaded and shared, the embedded script executes automatically when the image is viewed in a new browser tab.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the image.
Reproduction
To reproduce this vulnerability, create a malicious SVG file containing embedded JavaScript. Upload the file through the image upload interface in Slink version 1.4.9. After uploading, share the direct link to the image. The embedded script will execute automatically when the image is opened, without requiring a login.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
