CVE-2024-45965
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Published Oct 2, 2024
Updated: Oct 4, 2024
CWE ID 79
Summary
CVE-2024-45965 is a vulnerability affecting Contao 5.4.1. This issue enables authenticated admin users to upload SVG files, which can contain malicious JavaScript code. If an SVG file is accessed through the website, it may lead to a Cross-Site Scripting (XSS) attack, potentially allowing attackers to steal user data or execute arbitrary code on the target system. The vulnerable component has not been identified, but it is recommended that users upgrade to the latest version of Contao to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Contao