logo

Database

Server side cross-site scripting In contao/core-bundle

Description

Contao Vulnerable to Cross-Site Scripting (XSS) through SVG uploads

Impact

Users can upload SVG files with malicious code, which is then executed in the back end and/or front end.

Patches

Update to Contao 4.13.54, 5.3.30 or 5.5.6.

Workarounds

Remove svg,svgz from the allowed upload file types in the system settings and from contao.editable_files in the config.yaml.

References

https://contao.org/en/security-advisories/cross-site-scripting-through-svg-uploads

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-4TMTE – Vulnerability | Fluid Attacks Database