Gokapi Stored Cross-Site Scripting Vulnerability via SVG Hotlinking
Vulnerability
A stored cross-site scripting vulnerability has been identified in Gokapi, a self-hosted file sharing server, prior to version 2.2.3. This issue allows malicious authenticated users to upload SVG files, create hotlinks for them, and execute arbitrary JavaScript. The vulnerability arises because the hotlinking feature does not properly sanitize scripts embedded in the SVGs, enabling authenticated attackers to execute JavaScript in the context of the user.
Impact
Exploitation of this vulnerability allows authenticated users to execute arbitrary JavaScript, potentially leading to various malicious actions such as stealing cookies or session tokens.
Remediation
Users are advised to update to Gokapi version 2.2.3 or later, where this vulnerability has been patched.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
