PT-2019-15705 · Svg Sanitize · Svg-Sanitizer

Publicado

2019-11-11

·

Atualizado

2020-08-24

·

CVE-2019-18857

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions svg-sanitizer versions prior to 0.12.0
Description The issue concerns the mishandling of script and data values in attributes, which can be demonstrated by the presence of unexpected whitespace, such as in the javascript:alert substring. This indicates a potential problem with how the sanitizer processes certain types of input.
Recommendations For versions prior to 0.12.0, update to version 0.12.0 or later to resolve the issue. As a temporary workaround, consider restricting the input allowed for attributes to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-18857
GHSA-GF8J-V8X5-H9QP

Produtos afetados

Svg-Sanitizer