PT-2025-51748 · Spip+1 · Spip+1
Nu11Secur1Ty
·
Published
2025-12-16
·
Updated
2025-12-16
·
CVE-2023-53900
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Spip version 4.1.10
Description
Spip 4.1.10 is affected by a file upload issue. This allows attackers to upload malicious SVG files containing external links. An attacker can potentially trick administrators into clicking a crafted SVG logo, redirecting them to a dangerous URL due to insufficient file upload filtering. The vulnerability involves improper filtering of uploaded files, specifically SVG files, enabling the inclusion of external links within them.
Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict file uploads to trusted file types only. Implement stricter file upload validation to prevent the upload of SVG files with embedded external links.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Spip