Collax Security Gateway: anonymous reflected SVG cross-site scripting in the logo generator

An unauthenticated attacker who lures a victim to a crafted /.logo URL gains script execution in the admin origin, because the colour parameter reaches an active SVG document raw.

Advisory ID: TP-2026-068
Product: Collax Security Gateway (German UTM, firewall, mail and SSL-VPN appliance; also affects Collax Business Server and Groupware Suite)
Vulnerability type: Reflected cross-site scripting (CWE-79)
CVE: pending (MITRE CNA-LR)
CVSS 3.1: 9.3 (Critical) · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Vendor advisory: Collax release notes CSG 7.2.48
Affected versions: 7.2.46 and earlier
Fixed in: 7.2.48
Reported: 01 September 2026

Summary

The admin interface serves its branding logo from cgi-bin/generate-logo.cgi, aliased to /.logo. The script draws an SVG hexagon in a caller-chosen colour and returns it with Content-Type image/svg+xml. The c query parameter is read as a free-form string and concatenated raw into the style attribute of a element as stroke:#. A double quote closes the style attribute, /> closes the , and following markup is emitted verbatim into the SVG document. Because the response is an active image/svg+xml document, a top-level navigation to the crafted URL executes embedded script, and the alias is reachable without authentication.

Root cause

createOutline builds '<path id="outline" style="...stroke:'.$color.';..."' (generate-logo.cgi:173), concatenating the colour into a double-quoted style attribute with no encoding.
The colour comes from generate-logo.cgi:30 $q->param('c') || $opt->color, declared as a free string (generate-logo.cgi:14, type 's') with no ^[0-9a-fA-F]{3,6}$ check.
The sibling dimensions w and h are declared as integers (generate-logo.cgi:12-13, type 'i') and printed with %d (generate-logo.cgi:33), so they cannot carry markup, showing the colour was left unconstrained by oversight.
The response is set to image/svg+xml (generate-logo.cgi:21), so the injected markup renders as an active document on direct navigation.
No Apache header restricts the script, and /.logo is reachable without authentication as a branding asset for the pre-login page.

Proof of Concept

Schematically: a top-level navigation link to the logo asset with a crafted colour.

GET /.logo?c=<breakout from the style attribute with script markup> HTTP/1.1
Host: <gw>:8001

The response carries Content-Type: image/svg+xml, and the colour breaks out of the style attribute and the element. Only c is injectable: w=999"/>...&h=1 renders width='999' height='1', confirming w and h are coerced to integers. Verified at code level on 2026-09-01 under chroot+akrun; the browser firing follows from the active SVG content type and the appliance-wide absence of CSP.

Impact

  • Anonymous script execution in the admin origin of any victim who opens the crafted /.logo URL on a top-level navigation, with no account.
  • Disclosure of the non-HttpOnly auth_cookie on the admin origin, which is base64(user:password), and thus the plaintext admin password.
  • Forgery of administration RPC actions in the victim session on the same origin.
  • Full control of the UTM, firewall and mail gateway follows from administrator credential disclosure.

References

Is Something Like This in Your Software?

Our team found this vulnerability during its work. Have your applications tested by the same specialists, with a penetration test from turingpoint.