Spip 4.1.10 contains a file upload vulnerability that...
Low severity
Unreviewed
Published
Dec 16, 2025
to the GitHub Advisory Database
•
Updated Dec 16, 2025
Description
Published by the National Vulnerability Database
Dec 16, 2025
Published to the GitHub Advisory Database
Dec 16, 2025
Last updated
Dec 16, 2025
Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.
References