Description
Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.
Remediation
References
Related Vulnerabilities
Oracle Database Server Other Vulnerability (CVE-2001-0942)
WordPress Plugin Ultimate SMS Notifications for WooCommerce CSV Injection (1.4.1)
WordPress Other Vulnerability (CVE-2007-1049)
WordPress Plugin HDW Player (Video Player & Video Gallery) SQL Injection (2.4.2)
Apache Tomcat Improper Access Control Vulnerability (CVE-2014-7810)