Lucene search

K
osvGoogleOSV:CVE-2022-24278
HistoryJun 10, 2022 - 8:15 p.m.

CVE-2022-24278

2022-06-1020:15:07
Google
osv.dev
5
convert-svg-core
directory traversal
svg tags
vulnerability
software

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

56.1%

The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

56.1%

Related for OSV:CVE-2022-24278