cleantalk
Vulnerabilities and Security Researches

SVG Support, CVE-2022-23638

CVE, Research URL

CVE-2022-23638

Application

SVG Support

Published on
Feb 15, 2022
Research Description
svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no workaround available.
Affected versions
Min -, max 2.5.9.
Status
vulnerable