← Vulnerability feed

Vulnerability record · CVE-2024-55451 · published 16 December 2024

CVE-2024-55451: Ujcms cross-site scripting vulnerability

UUjcms · Ujcms

A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed by other backend users, it allows authenticated attackers to execute arbitrary JavaScript in the context of other backend users' browsers, potentially leading to the theft of sensitive tokens.

4.8 CVSS 3.1 Medium EPSS 0.32% · top 77.4% CWE-79 · Cross-site scripting
4.8CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed by other backend users, it allows authenticated attackers to execute arbitrary JavaScript in the context of other backend users' browsers, potentially leading to the theft of sensitive tokens.

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-55451 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-51350Ujcms authentication bypass by spoofing vulnerabilityA spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-…EPSS 1.3%9.8CVE-2023-34747Ujcms unrestricted file upload vulnerabilityFile upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.EPSS 20%9.8CVE-2023-34865Ujcms path traversal vulnerabilityDirectory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.EPSS 1.2%7.5CVE-2023-34878Ujcms observable discrepancy vulnerabilityAn issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-html/downl…EPSS 0.70%6.5CVE-2023-3231Ujcms information exposure vulnerabilityA vulnerability has been found in UJCMS up to 6.0.2 and classified as problematic. This vulnerability affects unknown code of the component ZIP Packa…EPSS 0.82%6.3CVE-2024-12483Ujcms improper authorization vulnerabilityA vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the comp…EPSS 3.6%6.1CVE-2023-24369Ujcms cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in UJCMS v4.1.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload …EPSS 0.43%5.4CVE-2024-55452Ujcms open redirect vulnerabilityA URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. T…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2024-55451), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.