Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-48591 — Disclosure of a Cross-Site Scripting (XSS) vulnerability in Inflectra SpiraTeam 7.2.00 via malicious SVG file upload, with impact analysis and remediation guidance. | Kitploit
Tools/GitHubGitHub/gcatt-as/cve-2024-48591
Vulnerability AnalysisWeb Application ExploitationWeb SecurityPapers & ResearchLearning & Education
GitHubgcatt-as/cve-2024-48591

CVE-2024-48591

Disclosure of a Cross-Site Scripting (XSS) vulnerability in Inflectra SpiraTeam 7.2.00 via malicious SVG file upload, with impact analysis and remediation guidance.

View Repository
31 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-48591

Vulnerability Disclosure: XSS in Inflectra SpiraTeam 7.2.00

Description

Inflectra SpiraTeam version 7.2.00 is vulnerable to Cross-Site Scripting (XSS) through the upload of specially crafted SVG files, which can execute JavaScript when viewed directly.

Vulnerability Type

Cross-Site Scripting (XSS)

Vendor

Inflectra

Affected Product

SpiraTeam 7.2.00

Affected Component

TestRuns section

Attack Type

Remote

Impact

  • Escalation of Privileges: Allows attackers to potentially gain higher access levels.

Attack Vectors

An attacker can upload a specially crafted SVG file containing JavaScript. When the file is viewed directly, the JavaScript executes in the viewer's browser.

References

  • OWASP: Cross-Site Scripting (XSS)
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Vendor Acknowledgment

Inflectra has confirmed the existence of this vulnerability.

Discoverer

Gareth Catterall https://www.anchorsec.co.uk

Note

Users of SpiraTeam 7.2.00 should update to the latest version.

Download Tool