CVE-2023-53900
EUVD-2023-6019016.12.2025, 18:16
Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| spip | spip | 4.1.10 |
𝑥
= Vulnerable software versions
Ubuntu Releases