Vigilance.fr - Contao: Cross Site Scripting via SVG Uploads, analyzed on 18/03/2025
May 2025 by Vigilance.fr
An attacker can trigger a Cross Site Scripting of Contao, via SVG Uploads, in order to run JavaScript code in the context of the web site.
Plus d'information sur : https://vigilance.fr/vulnerability/Contao-Cross-Site-Scripting-via-SVG-Uploads-46616