Описание
Fiora chat user avatar is vulnerable to XSS via SVG files
Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows arbitrary JavaScript execution when malicious SVG files are rendered by other users.
Пакеты
Наименование
fiora
npm
Затронутые версииВерсия исправления
= 1.0.0
Отсутствует
Связанные уязвимости
CVSS3: 5.4
nvd
4 месяца назад
Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows executes arbitrary JavaScript when malicious SVG files are rendered by other users.