SVG Support, CVE-2022-23638
- CVE, Research URL
- Home page URL
- Application
- Published on
- Feb 15, 2022
- Research Description
- svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no workaround available.
- Affected versions
-
Min -, max 2.5.9.
- Status
-
vulnerable