Количество 2
Количество 2
CVE-2020-7750
больше 5 лет назад
This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.
CVSS3: 9.6
EPSS: Низкий
GHSA-j977-g5vj-j27g
около 5 лет назад
Cross-Site Scripting in scratch-svg-renderer
CVSS3: 9.6
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-7750 This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function. | CVSS3: 9.6 | 7% Низкий | больше 5 лет назад | |
GHSA-j977-g5vj-j27g Cross-Site Scripting in scratch-svg-renderer | CVSS3: 9.6 | 7% Низкий | около 5 лет назад |
Уязвимостей на страницу
20