Improper Input Validation
CVE-2025-64747
Summary
Directus is a real-time API and App dashboard for managing SQL database content. A Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 11.13.0 that allows users with `upload files` and `edit item` permissions to inject malicious JavaScript through the Block Editor interface. Attackers can bypass Content Security Policy (CSP) restrictions by combining file uploads with iframe srcdoc attributes, resulting in persistent Cross-Site Scripting (XSS) execution. Version
- LOW
- NETWORK
- LOW
- UNCHANGED
- REQUIRED
- LOW
- LOW
- LOW
CWE-20 - Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
References
Advisory Timeline
- Published