
Disclosure of a Cross-Site Scripting (XSS) vulnerability in Inflectra SpiraTeam 7.2.00 via malicious SVG file upload, with impact analysis and remediation guidance.
Inflectra SpiraTeam version 7.2.00 is vulnerable to Cross-Site Scripting (XSS) through the upload of specially crafted SVG files, which can execute JavaScript when viewed directly.
Cross-Site Scripting (XSS)
Inflectra
SpiraTeam 7.2.00
TestRuns section
Remote
An attacker can upload a specially crafted SVG file containing JavaScript. When the file is viewed directly, the JavaScript executes in the viewer's browser.
Inflectra has confirmed the existence of this vulnerability.
Gareth Catterall https://www.anchorsec.co.uk
Users of SpiraTeam 7.2.00 should update to the latest version.