Duplicate Advisory: Contao allows admin an account to upload SVG file containing malicious JavaScript
Low severity
GitHub Reviewed
Published
Oct 2, 2024
to the GitHub Advisory Database
•
Updated Apr 22, 2025
Withdrawn
This advisory was withdrawn on Apr 22, 2025
Description
Published by the National Vulnerability Database
Oct 2, 2024
Published to the GitHub Advisory Database
Oct 2, 2024
Reviewed
Oct 2, 2024
Withdrawn
Apr 22, 2025
Last updated
Apr 22, 2025
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-vqqr-fgmh-f626. This link is maintained to preserve external references.
Original Description
Contao 5.4.1 allows an authenticated admin account to upload a SVG file containing malicious javascript code into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted javascript to the target.
References