Urgent.News

What's breaking now, across thousands of outlets.

More in Tech

I uploaded a green square to a Next.js store and got stored XSS

Upload a malicious SVG to the admin product image field and get stored XSS that fires for every visitor. The admin panel in OopsSec Store lets you upload product images, including SVGs.

  • Malicious SVG file uploaded to Next.js store enables stored XSS.
  • Admin access gained via SQL injection or weak MD5 hashing.
  • Server must inspect file bytes, not just Content-Type header.

More from Friday 25 September →