What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mehjabin Orthi Interactive SVG Image Map Builder plugin <= 1.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mehjabin Orthi Interactive SVG Image Map Builder plugin <= 1.0 versions.
Explanation of Vulnerability in Simple Terms
The Interactive SVG Image Map Builder contains a cross-site scripting (XSS) vulnerability that allows authenticated users with high privileges to inject malicious scripts. An attacker with admin or editor access can craft a malicious SVG image map that executes JavaScript in the browsers of other site users who view the affected page. The vulnerability requires user interaction—the victim must visit a page containing the injected content.
What an attacker can do
Inject JavaScript code that runs in other users' browsers when they view the affected SVG image map.
Potential impact on your site
A privileged user can inject malicious scripts affecting other site visitors, potentially stealing session tokens or redirecting users.
Conditions required to exploit
Attacker must have high-level site privileges (admin/editor role) and the victim must visit a page with the malicious SVG.
Key dates
External resources
Related vulnerabilities