MEDIUM6.1
GHSA-2ghm-r75j-pjx2
Cross-site Scripting in DOMSanitizer
Quick fix
GHSA-2ghm-r75j-pjx2 — rhukster/dom-sanitizer: upgrade to the fixed version with the command below.
composer require rhukster/dom-sanitizer:^1.0.7Details
DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/rhukster/dom-sanitizer
Introduced in:
0Fixed in: 1.0.7Fix
composer require rhukster/dom-sanitizer:^1.0.7