Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.
References
Configurations
No configuration.
History
24 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
CWE | CWE-434 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.4 |
Summary | (en) Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6. |
Information
Published : 2024-10-02 20:15
Updated : 2025-03-24 19:15
NVD link : CVE-2024-45965
Mitre link : CVE-2024-45965
CVE.ORG link : CVE-2024-45965
JSON object : View
Products Affected
No product.