Server side cross-site scripting In contao/core-bundle
Description
Contao Vulnerable to Cross-Site Scripting (XSS) through SVG uploads
Impact
Users can upload SVG files with malicious code, which is then executed in the back end and/or front end.
Patches
Update to Contao 4.13.54, 5.3.30 or 5.5.6.
Workarounds
Remove svg,svgz from the allowed upload file types in the system settings and from contao.editable_files in the config.yaml.
References
https://contao.org/en/security-advisories/cross-site-scripting-through-svg-uploads
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 4.13.54, 5.3.30, 5.5.6 |
Aliases
References