We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG.
Reserved 2025-08-07 | Published 2025-08-07 | Updated 2025-08-07 | Assigner mitreCWE-434 Unrestricted Upload of File with Dangerous Type
github.com/agorafoundation/agora/pull/556
github.com/...ommit/690ce56f254af01375b6033e53a80f14d7cc002e
github.com/...b61a4c4759/server/controller/userController.js
Support options