PT-2024-31859 · Contao · Contao
Published
2024-10-02
·
Updated
2025-11-13
·
CVE-2024-45965
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Contao version 5.4.1
Description
The issue allows an authenticated admin account to upload a SVG file containing malicious javascript code into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted javascript to the target.
Recommendations
For Contao version 5.4.1, consider disabling the SVG file upload feature for admin accounts until a patch is available to prevent potential Cross-Site Scripting (XSS) attacks or arbitrary code execution. Restrict access to the file upload module to minimize the risk of exploitation. Avoid accessing SVG files uploaded by admin accounts through the website until the issue is resolved.
Exploit
Fix
XSS
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Contao