<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 10:51:43 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-30248 — Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-30248</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; piccolo-orm piccolo_admin&lt;/p&gt;
&lt;p&gt;Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo&amp;#39;s admin panel allows media files to be uploaded. As a default, SVG is an allowed file type for upload. An attacker can upload an SVG which when loaded can allow arbitrary access to the admin page. This vulnerability was patched in version 1.3.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; piccolo-orm piccolo_admin&lt;/p&gt;
&lt;p&gt;Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo&amp;#39;s admin panel allows media files to be uploaded. As a default, SVG is an allowed file type for upload. An attacker can upload an SVG which when loaded can allow arbitrary access to the admin page. This vulnerability was patched in version 1.3.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-30248</guid>
    </item>
    <item>
      <title>GHSA-pmww-v6c9-7p83 — Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pmww-v6c9-7p83</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: piccolo-admin&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Piccolo&amp;#39;s admin panel provides the ability to upload media files and view them within the admin panel. If SVG is an allowed file type for upload; the default; an attacker can upload an SVG which when loaded under certain contexts allows for arbitrary access to the admin page.&lt;/p&gt;
&lt;p&gt;This access allows the following actions for example:
- The ability for an attacker to gain access to all data stored within the admin page
- The ability for an attacker to make any action within the admin page such as creating, modifying or deleting table records&lt;/p&gt;
&lt;p&gt;As the SVG is executed from the context of an authenticated admin session, any actions they may be able to make can be made by the attacker.&lt;/p&gt;
&lt;p&gt;*N.b. The relevant session cookies are inaccessible from JavaScript due to httponly being set so all exploits must be present within the SVG file*&lt;/p&gt;
&lt;p&gt;### PoC
_Complete instructions, including specific configuration details, to reproduce the vulnerability._&lt;/p&gt;
&lt;p&gt;Currently, this requires the ability for a user to have access to an administrators account in order to upload the malicious file for simplicity sake. I can however imagine situations where general end users have the ability to upload files which can later be managed via the admin page.&lt;/p&gt;
&lt;p&gt;See the following repository: [Piccolo XSS](https://github.com/Skelmis/piccolo_xss)&lt;/p&gt;
&lt;p&gt;1. Clone the repo
2. Run all migrations &amp;amp; create an admin user
3. Run `app.py` as a FastAPI application
4. Login to the admin page
5. Create a new task and upload the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: piccolo-admin&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Piccolo&amp;#39;s admin panel provides the ability to upload media files and view them within the admin panel. If SVG is an allowed file type for upload; the default; an attacker can upload an SVG which when loaded under certain contexts allows for arbitrary access to the admin page.&lt;/p&gt;
&lt;p&gt;This access allows the following actions for example:
- The ability for an attacker to gain access to all data stored within the admin page
- The ability for an attacker to make any action within the admin page such as creating, modifying or deleting table records&lt;/p&gt;
&lt;p&gt;As the SVG is executed from the context of an authenticated admin session, any actions they may be able to make can be made by the attacker.&lt;/p&gt;
&lt;p&gt;*N.b. The relevant session cookies are inaccessible from JavaScript due to httponly being set so all exploits must be present within the SVG file*&lt;/p&gt;
&lt;p&gt;### PoC
_Complete instructions, including specific configuration details, to reproduce the vulnerability._&lt;/p&gt;
&lt;p&gt;Currently, this requires the ability for a user to have access to an administrators account in order to upload the malicious file for simplicity sake. I can however imagine situations where general end users have the ability to upload files which can later be managed via the admin page.&lt;/p&gt;
&lt;p&gt;See the following repository: [Piccolo XSS](https://github.com/Skelmis/piccolo_xss)&lt;/p&gt;
&lt;p&gt;1. Clone the repo
2. Run all migrations &amp;amp; create an admin user
3. Run `app.py` as a FastAPI application
4. Login to the admin page
5. Create a new task and upload the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pmww-v6c9-7p83</guid>
    </item>
  </channel>
</rss>
