Description
PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle upload files in the findings import feature. This vulnerability is capable of uploading dangerous type of file to server leading to XSS attacks and potentially other forms of code injection. Users are advised to update to 1.7.7 as soon as possible. There are no known workarounds for this issue.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_confirm
https://github.com/Patrowl/PatrowlManager/security/advisories/GHSA-5hc9-6hq4-2xfx
Patch, Third Party Advisory x_refsource_misc
https://github.com/Patrowl/PatrowlManager/commit/2287c9715d2e7ef11b44bb0ad4a57727654f2203
Exploit, Patch, Third Party Advisory x_refsource_misc
https://huntr.dev/bounties/17324785-f83a-4058-ac40-03f2bfa16399/
Scores
CVSS v3
7.4
EPSS
0.0228
EPSS Percentile
84.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Details
CWE
CWE-434
Status
published
Products (1)
patrowl/patrowlmanager
< 1.7.7
Published
Dec 14, 2021
Tracked Since
Feb 18, 2026