CVE-2024-28147 - CVE House
Back to Database
Status published Unknown CVE-2024-28147

Unrestricted Upload of Files in edu-sharing

Vulnerability Description

An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may upload an HTML file that includes malicious JavaScript code which will be executed if a user visits the direct URL of the collection preview image (Stored Cross Site Scripting). It is also possible to upload SVG files that include nested XML entities. Those are parsed when a user visits the direct URL of the collection preview image, which may be utilized for a Denial of Service attack. This issue affects edu-sharing: <8.0.8-RC2, <8.1.4-RC0, <9.0.0-RC19.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28147

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Kai Zimmermann, SEC Consult Vulnerability Lab

Affected Vendor

metaVentis GmbH

View all reports →

Affected Software

edu-sharing
Vulnerable Versions:
<8.0.8-RC2, <8.1.4-RC0, <9.0.0-RC19

Timeline

Official Publish: June 20th, 2024
Last Modified: February 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)