Описание
Directory traversal in convert-svg-core
The package convert-svg-core before 0.6.4 is vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.
Пакеты
Наименование
convert-svg-core
npm
Затронутые версииВерсия исправления
< 0.6.4
0.6.4
Связанные уязвимости
CVSS3: 7.5
nvd
больше 3 лет назад
The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.