CVE-2023-53900: Spip 4.1.10 Admin Account Spoofing via Malicious SVG Upload
Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53900?
CVE-2023-53900 is classified as a high severity vulnerability due to the potential for attackers to exploit it via malicious file uploads.
How do I fix CVE-2023-53900?
To fix CVE-2023-53900, ensure that your Spip installation is updated to the latest version, which addresses file upload filtering issues.
What types of files are affected by CVE-2023-53900?
CVE-2023-53900 specifically affects SVG files that can be uploaded and contain embedded external links.
Who is impacted by CVE-2023-53900?
Administrators using Spip version 4.1.10 are primarily impacted by CVE-2023-53900 due to the file upload vulnerability.
Can CVE-2023-53900 lead to phishing attacks?
Yes, CVE-2023-53900 can lead to phishing attacks as attackers may trick users into clicking on malicious SVG filenames that redirect to harmful URLs.