VDB
Sign up
—

DRUPAL-CONTRIB-2020-005

Details

SVG Formatter module provides support for using SVG images on your website.

This security release fixes third-party dependencies included in or required by SVG Formatter. [XSS bypass using entities and tab](https://github.com/darylldoyle/svg-sanitizer/issues/31).

This vulnerability is mitigated by the fact that an attacker must be able to upload SVG files.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/svg_formatter
Introduced in: 0Fixed in: 1.12.0

Upgrade drupal/svg_formatter to 1.12.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References