Stored XSS Vulnerability in Authentik by GoAuthentik
CVE-2024-11623
4.8MEDIUM
What is CVE-2024-11623?
The Authentik project is vulnerable to stored XSS attacks that can occur through the upload of specially crafted SVG files used as application icons. This vulnerability allows authenticated admin users to inadvertently leverage this flaw by uploading malicious SVG content. The vulnerability was addressed in the 2024.10.4 release, underscoring the importance of updating to this version to mitigate associated risks.
Affected Version(s)
authentik 0 < 2024.10.4