Описание
Cross-site Scripting in Grav
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
Пакеты
Наименование
getgrav/grav
composer
Затронутые версииВерсия исправления
<= 1.7.0-beta.7
1.7.0-beta.8
Связанные уязвимости
CVSS3: 6.1
nvd
больше 6 лет назад
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.