« Volver al listado

CVE-2024-45965

Estado: AnalizadaMedia (5.4)—

Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-45965",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-45965",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-02T20:29:10.374330Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 3.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "Contao",
          "product": "Contao",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.0",
              "lessThan": "4.13.54",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.0.0",
              "lessThan": "5.3.30",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.4.0",
              "lessThan": "5.5.6",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:contao:contao:5.4.1:*:*:*:*:*:*:*"
          ],
          "vendor": "contao",
          "product": "contao",
          "versions": [
            {
              "status": "affected",
              "version": "5.4.1"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-10-02T20:15:11.320",
  "references": [
    {
      "url": "https://contao.org/en/security-advisories/cross-site-scripting-through-svg-uploads",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://grimthereaperteam.medium.com/contao-5-4-1-malicious-file-upload-xss-in-svg-30edb8820ecb",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6."
    },
    {
      "lang": "es",
      "value": "Contao 5.4.1 permite que una cuenta de administrador autenticada cargue un archivo SVG que contenga código JavaScript malicioso en el sistema de destino. Si se accede al archivo a través del sitio web, podría provocar un ataque de Cross-Site Scripting (XSS) o ejecutar código arbitrario a través de un código JavaScript manipulado específicamente para el objetivo."
    }
  ],
  "lastModified": "2026-06-17T07:55:04.263",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F2B78795-5DC9-4D54-846D-B295A85D3FEE",
              "versionEndExcluding": "4.13.54",
              "versionStartIncluding": "4.0"
            },
            {
              "criteria": "cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DC1431E-AC3C-4A63-B1F1-9AEB22608F7F",
              "versionEndExcluding": "5.3.30",
              "versionStartIncluding": "5.0.0"
            },
            {
              "criteria": "cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C5E0EF8-382F-4886-9DD0-7A15704CB0BA",
              "versionEndExcluding": "5.5.6",
              "versionStartIncluding": "5.4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}