Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fqx8-v33p-4qcc

Опубликовано: 14 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.2

Описание

Cross-site Scripting in enshrined/svg-sanitize

Impact

SVG sanitizer library before version 0.15.0 did not remove HTML elements wrapped in a CDATA section. As a result, SVG content embedded in HTML (fetched as text/html) was susceptible to cross-site scripting. Plain SVG files (fetched as image/svg+xml) were not affected.

Patches

This issue is fixed in 0.15.0 and higher.

Workarounds

There is currently no workaround available without upgrading.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

enshrined/svg-sanitize

composer
Затронутые версииВерсия исправления

< 0.15.0

0.15.0

EPSS

Процентиль: 27%
0.00098
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.2
ubuntu
почти 4 года назад

svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no workaround available.

CVSS3: 6.2
nvd
почти 4 года назад

svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no workaround available.

EPSS

Процентиль: 27%
0.00098
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-79