PT-2025-51748 · Spip+1 · Spip+1

Nu11Secur1Ty

·

Published

2025-12-16

·

Updated

2025-12-16

·

CVE-2023-53900

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spip version 4.1.10
Description Spip 4.1.10 is affected by a file upload issue. This allows attackers to upload malicious SVG files containing external links. An attacker can potentially trick administrators into clicking a crafted SVG logo, redirecting them to a dangerous URL due to insufficient file upload filtering. The vulnerability involves improper filtering of uploaded files, specifically SVG files, enabling the inclusion of external links within them.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict file uploads to trusted file types only. Implement stricter file upload validation to prevent the upload of SVG files with embedded external links.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-53900

Affected Products

Debian
Spip