MyEMS Stored Cross-Site Scripting Vulnerability in Admin Backend

Vulnerability

A stored cross-site scripting vulnerability has been identified in MyEMS versions prior to 6.4.0. The issue resides in the Admin Backend, specifically within the 'on_post' function of 'myems-api/core/svg.py'. This vulnerability allows remote attackers to inject malicious SVG data that is saved and later executed, potentially leading to session cookie theft and account takeover, including administrative accounts.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected content. This could lead to session hijacking, with an attacker able to take over the accounts of users, including administrators.

Reproduction

To reproduce this vulnerability, log in as an admin user and navigate to the SVG code upload page. Upload a crafted SVG payload containing a script, such as one using a 'foreignObject' to include an iframe with a JavaScript URL. After saving, the injected script will execute, demonstrating the cross-site scripting vulnerability.

Remediation

Users are advised to upgrade to MyEMS version 6.5.0, where this vulnerability has been fixed.

Added: Jul 10, 2026, 4:28 AM
Updated: Jul 10, 2026, 4:28 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.9
remediation
0.0
relevance
9.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.