VDB
Sign up
MEDIUM5.4

GHSA-59cf-m7v5-wh5w

Cross-Site Scripting in SVG Sanitizer

Quick fix

GHSA-59cf-m7v5-wh5w — t3g/svg-sanitizer: upgrade to the fixed version with the command below.

composer require t3g/svg-sanitizer:^1.0.3

Details

Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at all. Albeit the markup is not valid it still is evaluated in browsers and leads to cross-site scripting.

An updated version 1.0.3 is available from the TYPo3 extension manager and at https://extensions.typo3.org/extension/download/svg_sanitizer/1.0.3/zip/ Users of the extension are advised to update the extension as soon as possible.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/t3g/svg-sanitizer
Introduced in: 0Fixed in: 1.0.3
Fixcomposer require t3g/svg-sanitizer:^1.0.3

References