VDB
Sign up
MEDIUM4.8

GHSA-gcqv-f29m-67gr

October Rain has Stored XSS via SVG Filter Bypass

Quick fix

GHSA-gcqv-f29m-67gr — october/rain: upgrade to the fixed version with the command below.

composer require october/rain:^4.1.10

Details

A stored cross-site scripting (XSS) vulnerability was identified in the SVG sanitization logic. The regex pattern used to strip `on*` event handler attributes could be bypassed using a crafted payload that exploits how the pattern matches attribute boundaries.

### Impact - Stored XSS via malicious SVG files uploaded through the Media Manager - Could allow privilege escalation if a superuser views or embeds the malicious SVG - Requires authenticated backend access with media upload permissions (`media.library.create`) - SVG must be viewed or embedded in a page to trigger

### Patches The vulnerability has been patched in v3.7.14 and v4.1.10. All users are encouraged to upgrade to the latest patched version.

### Workarounds If upgrading immediately is not possible: - Disable SVG uploads by adding `svg` to the blocked extensions in media configuration - Set `media.clean_vectors` to `true` in configuration (enabled by default)

### References - Reported by Pentest-Tools.com

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/october/rain
Introduced in: 4.0.0Fixed in: 4.1.10
Fixcomposer require october/rain:^4.1.10
Packagist/october/rain
Introduced in: 0Fixed in: 3.7.14
Fixcomposer require october/rain:^3.7.14

References