Stored Cross-Site Scripting (XSS) vulnerability type in Apidog in the version 2.7.15, where SVG image uploads are not properly sanitized. This allows attackers to embed malicious scripts in SVG files by sending a POST request to '/api/v1/user-avatar', which are then stored on the server and executed in the context of any user accessing the compromised resource.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-Site Scripting (XSS) vulnerability type in Apidog in the version 2.7.15, where SVG image uploads are not properly sanitized. This allows attackers to embed malicious scripts in SVG files by sending a POST request to '/api/v1/user-avatar', which are then stored on the server and executed in the context of any user accessing the compromised resource. | |
| Title | Stored Cross-Site Scripting (XSS) in Apidog web platform | |
| First Time appeared |
Apidog
Apidog apidog Web Platform |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:apidog:apidog_web_platform:2.7.15:*:*:*:*:*:*:* | |
| Vendors & Products |
Apidog
Apidog apidog Web Platform |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-02-04T09:56:45.513Z
Reserved: 2025-04-16T09:09:36.724Z
Link: CVE-2025-41085
No data.
Status : Received
Published: 2026-02-04T10:16:03.270
Modified: 2026-02-04T10:16:03.270
Link: CVE-2025-41085
No data.