Medium severity5.4NVD Advisory· Published Dec 7, 2023· Updated Jun 17, 2026
CVE-2023-46857
CVE-2023-46857
Description
Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is required for exploitation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- census-labs.com/news/2023/11/08/weak-svg-asset-filtering-mechanism-in-squidex-cms/nvdExploit
- support.squidex.io/c/news/9nvdVendor Advisory
- www.openwall.com/lists/oss-security/2023/11/08/4nvdMailing List
News mentions
0No linked articles in our index yet.