CVE-2018-25157 PUBLISHED

Phraseanet 4.0.3 Stored XSS via Document Upload

Assigner: VulnCheck
Reserved: 11.02.2026 Published: 11.02.2026 Updated: 11.02.2026

Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through crafted file names during document uploads. Attackers can upload files with embedded SVG scripts that execute in the browser, potentially stealing cookies or redirecting users when the file is viewed.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor Phraseanet
Product Phraseanet DAM Open Source
Versions
  • Version <= 4.0.3 is affected
  • Version 4.0.4-dev is affected

Credits

  • Krzysztof Szulski finder

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE