CVE-2024-51492
Zusam is a free and open-source way to self-host private forums. Prior to version 0.5.6, specially crafted SVG files uploaded to the service as images allow for unrestricted script execution on (raw) image load. With certain payloads, theft of the target user’s long-lived session token is possible. Note that Zusam, at the time of writing, uses a user’s static API key as a long-lived session token, and these terms can be used interchangeably on the platform. This session token/API key remains valid indefinitely, so long as the user doesn’t expressly request a new one via their Settings page. Version 0.5.6 fixes the cross-site scripting vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.47%
- Percentil entre todas las CVEs puntuadas: 39
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1189Drive-by Compromiseinitial access95 % - Impacto principal
T1059.007JavaScriptexecution85 % - Impacto secundario
T1078.001Default Accountsstealth · persistence · privilege escalation · initial access90 %
XSS mediante SVG malicioso (CWE-79) permite ejecución de JavaScript en navegador para robar token de sesión/API key indefinidamente válido. Vector UI:R confirma interacción del usuario.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-51492",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-51492",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-11-01T17:26:05.835349Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.3,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "zusam",
"product": "zusam",
"versions": [
{
"status": "affected",
"version": "< 0.5.6"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:zusam:zusam:*:*:*:*:*:*:*:*"
],
"vendor": "zusam",
"product": "zusam",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "0.5.6",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-11-01T17:15:18.930",
"references": [
{
"url": "https://github.com/zusam/zusam/commit/5930fdf86fa4abed01f0b345c8ec3c443656db9a",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/zusam/zusam/releases/tag/0.5.6",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/zusam/zusam/security/advisories/GHSA-96fx-5rqv-jfxh",
"source": "security-advisories@github.com"
},
{
"url": "https://pfeister.dev/CVE-2024-51492",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Zusam is a free and open-source way to self-host private forums. Prior to version 0.5.6, specially crafted SVG files uploaded to the service as images allow for unrestricted script execution on (raw) image load. With certain payloads, theft of the target user’s long-lived session token is possible. Note that Zusam, at the time of writing, uses a user’s static API key as a long-lived session token, and these terms can be used interchangeably on the platform. This session token/API key remains valid indefinitely, so long as the user doesn’t expressly request a new one via their Settings page. Version 0.5.6 fixes the cross-site scripting vulnerability."
},
{
"lang": "es",
"value": "Zusam es una forma gratuita y de código abierto de alojar foros privados. Antes de la versión 0.5.6, los archivos SVG especialmente manipulados que se subían al servicio como imágenes permitían la ejecución sin restricciones de scripts al cargar imágenes (sin procesar). Con ciertos payloads, es posible el robo del token de sesión de larga duración del usuario objetivo. Tenga en cuenta que, al momento de escribir este artículo, Zusam usa la clave API estática de un usuario como token de sesión de larga duración, y estos términos se pueden usar indistintamente en la plataforma. Este token de sesión/clave API sigue siendo válido indefinidamente, siempre y cuando el usuario no solicite expresamente uno nuevo a través de su página de Configuración. La versión 0.5.6 corrige la vulnerabilidad de cross site scripting."
}
],
"lastModified": "2026-06-17T08:05:47.863",
"sourceIdentifier": "security-advisories@github.com"
}