—
DRUPAL-CONTRIB-2024-051
Details
This module enables you to animate an SVG graphic by selecting certain rows in a view.
The module doesn't sufficiently sanitize the SVG file before embedding it into the html.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission to upload SVG files.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/views_svg_animation
Introduced in:
0Fixed in: 1.0.1Upgrade drupal/views_svg_animation to 1.0.1 or newer (ecosystem packagist:https://packages.drupal.org/8).