Collax Security Gateway: anonymous reflected SVG cross-site scripting in the logo generator
An unauthenticated attacker who lures a victim to a crafted /.logo URL gains script execution in the admin origin, because the colour parameter reaches an active SVG document raw.
Advisory ID: TP-2026-068
Product: Collax Security Gateway (German UTM, firewall, mail and SSL-VPN appliance; also affects Collax Business Server and Groupware Suite)
Vulnerability type: Reflected cross-site scripting (CWE-79)
CVE: pending (MITRE CNA-LR)
CVSS 3.1: 9.3 (Critical) · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Vendor advisory: Collax release notes CSG 7.2.48
Affected versions: 7.2.46 and earlier
Fixed in: 7.2.48
Reported: 01 September 2026
Summary
The admin interface serves its branding logo from cgi-bin/generate-logo.cgi, aliased to /.logo. The script draws an SVG hexagon in a caller-chosen colour and returns it with Content-Type image/svg+xml. The c query parameter is read as a free-form string and concatenated raw into the style attribute of a
Root cause
createOutline builds '<path id="outline" style="...stroke:'.$color.';..."' (generate-logo.cgi:173), concatenating the colour into a double-quoted style attribute with no encoding.
The colour comes from generate-logo.cgi:30 $q->param('c') || $opt->color, declared as a free string (generate-logo.cgi:14, type 's') with no ^[0-9a-fA-F]{3,6}$ check.
The sibling dimensions w and h are declared as integers (generate-logo.cgi:12-13, type 'i') and printed with %d (generate-logo.cgi:33), so they cannot carry markup, showing the colour was left unconstrained by oversight.
The response is set to image/svg+xml (generate-logo.cgi:21), so the injected markup renders as an active document on direct navigation.
No Apache header restricts the script, and /.logo is reachable without authentication as a branding asset for the pre-login page.
Proof of Concept
Schematically: a top-level navigation link to the logo asset with a crafted colour.
GET /.logo?c=<breakout from the style attribute with script markup> HTTP/1.1
Host: <gw>:8001
The response carries Content-Type: image/svg+xml, and the colour breaks out of the style attribute and the
Impact
- Anonymous script execution in the admin origin of any victim who opens the crafted /.logo URL on a top-level navigation, with no account.
- Disclosure of the non-HttpOnly auth_cookie on the admin origin, which is base64(user:password), and thus the plaintext admin password.
- Forgery of administration RPC actions in the victim session on the same origin.
- Full control of the UTM, firewall and mail gateway follows from administrator credential disclosure.
References
Is Something Like This in Your Software?
Our team found this vulnerability during its work. Have your applications tested by the same specialists, with a penetration test from turingpoint.
