CVE-2024-45965: XSS

Published Oct 2, 2024
·
Updated

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-vqqr-fgmh-f626. This link is maintained to preserve external references.

Original Description

Contao 5.4.1 allows an authenticated admin account to upload a SVG file containing malicious javascript code into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted javascript to the target.

Other sources

Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.

— NVD

Affected Software

4 affected components
composer/contao/contao<=5.4.1
Contao Contao>=4.0<4.13.54
Contao Contao>=5.0.0<5.3.30
Contao Contao>=5.4.0<5.5.6

Event History

Oct 2, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software
Advisory Published
via GitHub·09:30 PM
Apr 22, 2025
Withdrawn
via GitHub·03:17 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-45965?

CVE-2024-45965 is classified as a high-severity vulnerability due to its potential for Cross-Site Scripting attacks.

2

How do I fix CVE-2024-45965?

To fix CVE-2024-45965, upgrade to Contao version 5.4.2 or later where the SVG file upload vulnerability has been addressed.

3

Who is affected by CVE-2024-45965?

CVE-2024-45965 affects users of Contao version 5.4.1 who have an authenticated admin account.

4

What can attackers achieve with CVE-2024-45965?

Attackers can exploit CVE-2024-45965 to execute malicious JavaScript, allowing for potential Cross-Site Scripting (XSS) or arbitrary code execution.

5

Is CVE-2024-45965 a local or remote vulnerability?

CVE-2024-45965 is a local vulnerability that requires an authenticated admin account to exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203