
Stored XSS Vulnerability in OopsSec Store Next.js Application via Malicious SVG Upload
A stored cross-site scripting (XSS) vulnerability was demonstrated in OopsSec Store, an intentionally vulnerable Next.js e-commerce application used for security training. The vulnerability allows attackers with admin access to upload malicious SVG files containing JavaScript through the product image upload feature. The server only validates the Content-Type header, which is client-controlled, and accepts SVG files in the allowed formats list. The frontend renders SVGs using the tag, which executes embedded scripts, causing the JavaScript to run for every visitor viewing the product page. The vulnerability requires admin access, which can be obtained through SQL injection or weak MD5 password hashing as documented in separate attack chains.