CVE-2024-51492 - CVE House
Back to Database
Status published High CVE-2024-51492

Zusam vulnerable to stored XSS, allowing token theft via crafted SVG

Vulnerability Description

Zusam is a free and open-source way to self-host private forums. Prior to version 0.5.6, specially crafted SVG files uploaded to the service as images allow for unrestricted script execution on (raw) image load. With certain payloads, theft of the target user’s long-lived session token is possible. Note that Zusam, at the time of writing, uses a user’s static API key as a long-lived session token, and these terms can be used interchangeably on the platform. This session token/API key remains valid indefinitely, so long as the user doesn’t expressly request a new one via their Settings page. Version 0.5.6 fixes the cross-site scripting vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-51492

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

zusam
Vulnerable Versions:
< 0.5.6

Timeline

Official Publish: November 1st, 2024
Last Modified: November 1st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L

Weaknesses (CWE)