Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3w5m-3c69-745h

Опубликовано: 16 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 8.8

Описание

Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.

Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.

EPSS

Процентиль: 11%
0.00037
Низкий

4.8 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 месяцев назад

Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.

CVSS3: 8.8
nvd
около 2 месяцев назад

Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.

CVSS3: 8.8
debian
около 2 месяцев назад

Spip 4.1.10 contains a file upload vulnerability that allows attackers ...

EPSS

Процентиль: 11%
0.00037
Низкий

4.8 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-79