Количество 2
Количество 2
CVE-2019-18857
около 6 лет назад
darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript	:alert substring.
CVSS3: 7.5
EPSS: Низкий
GHSA-gf8j-v8x5-h9qp
около 6 лет назад
XSS in enshrined/svg-sanitize due to mishandled script and data values in attributes
CVSS3: 7.5
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-18857 darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript	:alert substring. | CVSS3: 7.5 | 0% Низкий | около 6 лет назад | |
GHSA-gf8j-v8x5-h9qp XSS in enshrined/svg-sanitize due to mishandled script and data values in attributes | CVSS3: 7.5 | 0% Низкий | около 6 лет назад |
Уязвимостей на страницу
20