CVE 6.4 MEDIUM

CVE-2025-55135_CVE-2025-55135

6.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Description

In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG.

AI Analysis

A cross-site scripting (XSS) vulnerability exists in Agora Foundation's Agora platform. It allows attackers to inject malicious scripts via profile pictures, exploiting the system by using non-image formats like SVG. This could lead to unauthorized actions on behalf of users.

Basic Information

ID CVE-2025-55135
Source mitre
Published Aug 7, 2025 at 00:00
Modified Aug 7, 2025 at 16:06

Affected Product

Vendor Agora Foundation
Product Agora
Affected Versions Agora Foundation Agora 0

CWE Classification

AI Assessment

AI Severity Medium
Vendor Agora Foundation
Product Agora
Version version before commit 690ce56

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.