—
DRUPAL-CONTRIB-2020-005
Details
SVG Formatter module provides support for using SVG images on your website.
This security release fixes third-party dependencies included in or required by SVG Formatter. [XSS bypass using entities and tab](https://github.com/darylldoyle/svg-sanitizer/issues/31).
This vulnerability is mitigated by the fact that an attacker must be able to upload SVG files.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/svg_formatter
Introduced in:
0Fixed in: 1.12.0Upgrade drupal/svg_formatter to 1.12.0 or newer (ecosystem packagist:https://packages.drupal.org/8).