# CVE-2024-48591
# Vulnerability Disclosure: XSS in Inflectra SpiraTeam 7.2.00
## Description
Inflectra SpiraTeam version 7.2.00 is vulnerable to Cross-Site Scripting (XSS) through the upload of specially crafted SVG files, which can execute JavaScript when viewed directly.
## Vulnerability Type
Cross-Site Scripting (XSS)
## Vendor
Inflectra
## Affected Product
SpiraTeam 7.2.00
## Affected Component
TestRuns section
## Attack Type
Remote
## Impact
- **Escalation of Privileges**: Allows attackers to potentially gain higher access levels.
## Attack Vectors
An attacker can upload a specially crafted SVG file containing JavaScript. When the file is viewed directly, the JavaScript executes in the viewer's browser.
## References
- [OWASP: Cross-Site Scripting (XSS)](https://owasp.org/www-community/attacks/xss/)
- [CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')](https://cwe.mitre.org/data/definitions/79.html)
## Vendor Acknowledgment
Inflectra has confirmed the existence of this vulnerability.
## Discoverer
Gareth Catterall
## Note
Users of SpiraTeam 7.2.00 should update to the latest version.
[4.0K] /data/pocs/a30d403d475ff572c9953d653d08adcc89d82a01
└── [1.1K] README.md
0 directories, 1 file