CVE-2024-30248 HIGH

CVE-2024-30248: Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page

Vendor Piccolo-Orm
Product piccolo_admin
Weakness CWE-79 · XSS
Published April 2, 2024
Last update August 2, 2024

CVSS base score

7.7/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel allows media files to be uploaded. As a default, SVG is an allowed file type for upload. An attacker can upload an SVG which when loaded can allow arbitrary access to the admin page. This vulnerability was patched in version 1.3.2.

Key dates

02Disclosure timeline

April 2, 2024 CVE published
August 2, 2024 Record updated