MEDIUM5.4
GHSA-59cf-m7v5-wh5w
Cross-Site Scripting in SVG Sanitizer
Quick fix
GHSA-59cf-m7v5-wh5w — t3g/svg-sanitizer: upgrade to the fixed version with the command below.
composer require t3g/svg-sanitizer:^1.0.3Details
Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at all. Albeit the markup is not valid it still is evaluated in browsers and leads to cross-site scripting.
An updated version 1.0.3 is available from the TYPo3 extension manager and at https://extensions.typo3.org/extension/download/svg_sanitizer/1.0.3/zip/ Users of the extension are advised to update the extension as soon as possible.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/t3g/svg-sanitizer
Introduced in:
0Fixed in: 1.0.3Fix
composer require t3g/svg-sanitizer:^1.0.3