Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page
CVE-2024-30248

7.7HIGH

Key Information:

Vendor
CVE Published:
2 April 2024

What is CVE-2024-30248?

An arbitrary file upload vulnerability exists in the Piccolo Admin interface, which is designed for managing content in Python applications. The system permits the uploading of various media files, including SVG files, without adequate verification measures. This flaw enables attackers to leverage SVG files to gain unauthorized access to the administrative functions of the application. The vulnerability was corrected in version 1.3.2, underscoring the importance of updating to secure versions to mitigate the associated risks.

Affected Version(s)

piccolo_admin >= 1.2.0, < 1.3.2

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.