Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.
References
Link | Resource |
---|---|
https://contao.org/en/security-advisories/cross-site-scripting-through-svg-uploads | Vendor Advisory |
https://grimthereaperteam.medium.com/contao-5-4-1-malicious-file-upload-xss-in-svg-30edb8820ecb | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Jul 2025, 14:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://contao.org/en/security-advisories/cross-site-scripting-through-svg-uploads - Vendor Advisory | |
References | () https://grimthereaperteam.medium.com/contao-5-4-1-malicious-file-upload-xss-in-svg-30edb8820ecb - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* | |
First Time |
Contao contao
Contao |
24 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
CWE | CWE-434 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.4 |
Summary | (en) Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6. |
Information
Published : 2024-10-02 20:15
Updated : 2025-07-03 14:16
NVD link : CVE-2024-45965
Mitre link : CVE-2024-45965
CVE.ORG link : CVE-2024-45965
JSON object : View
Products Affected
contao
- contao