Description
Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
4.1.10
Credits
nu11secur1ty
References
www.exploit-db.com/exploits/51557 (ExploitDB-51557)
www.spip.net/en_rubrique25.html (SPIP Product Webpage)
www.vulncheck.com/...count-spoofing-via-malicious-svg-upload (VulnCheck Advisory: Spip 4.1.10 Admin Account Spoofing via Malicious SVG Upload)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.