PT-2024-31859 · Contao · Contao

Published

2024-10-02

·

Updated

2025-11-13

·

CVE-2024-45965

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Contao version 5.4.1
Description The issue allows an authenticated admin account to upload a SVG file containing malicious javascript code into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted javascript to the target.
Recommendations For Contao version 5.4.1, consider disabling the SVG file upload feature for admin accounts until a patch is available to prevent potential Cross-Site Scripting (XSS) attacks or arbitrary code execution. Restrict access to the file upload module to minimize the risk of exploitation. Avoid accessing SVG files uploaded by admin accounts through the website until the issue is resolved.

Exploit

Fix

XSS

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-45965
GHSA-MRW8-5368-PHM3

Affected Products

Contao