VDB
Sign up
—

DRUPAL-CONTRIB-2024-050

Details

This module enables you to embed the content of an SVG file into the body html of a node and optionally allows to translate text contained within the image.

The module doesn't sufficiently sanitize the SVG file before embedding it into the html.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to upload SVG files, and the permission to use a text format that includes the SVG embed filter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/svg_embed
Introduced in: 0Fixed in: 2.1.2

Upgrade drupal/svg_embed to 2.1.2 or newer (ecosystem packagist:https://packages.drupal.org/8).

References