---
id: CVE-2018-25157
title: >-
  Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that
  allows authenticated users to inject malicious scripts through crafted file
  names during document uploads
summary: >-
  Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that
  allows authenticated users to inject malicious scripts through crafted file
  names during document uploads. Attackers can upload files with embedded SVG
  scripts th…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: Phraseanet
product: Phraseanet DAM Open Source
affected:
  - dam_open_source <= 4.0.3
  - dam_open_source 4.0.4-dev
published: '2026-02-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:16:42.700'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-25157'
references:
  - url: 'https://www.exploit-db.com/exploits/46935'
    label: disclosure@vulncheck.com
  - url: 'https://www.phraseanet.com'
    label: disclosure@vulncheck.com
  - url: 'https://www.phraseanet.com/en/download/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/phraseanet-stored-xss-via-document-upload
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-02-11T21:09:30.815869Z'
epss: 0.00266
epssPercentile: 0.1699
ingestedAt: '2026-10-08T16:52:14.671Z'
---

## Overview

Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through crafted file names during document uploads. Attackers can upload files with embedded SVG scripts that execute in the browser, potentially stealing cookies or redirecting users when the file is viewed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
