Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

21Ko

#44108of 53,624
6.1Total CVSS
Vulnerabilities · 1
PT-2020-12920
6.1
2020-04-17
Svg2Png · Svg2Png · CVE-2020-11887
**Name of the Vulnerable Software and Affected Versions** svg2png version 4.1.1 **Description** The issue allows for XSS with resultant SSRF via JavaScript inside an SVG document. This can be exploited when JavaScript code is embedded inside an SVG document. **Recommendations** For svg2png version 4.1.1, consider disabling the processing of JavaScript inside SVG documents until a patch is available. Restrict the upload and processing of SVG files to minimize the risk of exploitation.