Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33876
HistoryJan 24, 2022 - 11:14 a.m.

Directory Traversal

2022-01-2411:14:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
vulnerability
svg file handler
arbitrary files
file system
specially crafted svg

EPSS

0.002

Percentile

57.9%

convert-svg-core, convert-svg-to-png and convert-svg-to-jpeg are vulnerable to directory traversal. The vulnerability exists because of the code of the component SVG File Handler which allows an attacker to read arbitrary files from the file system and then show the file content using a specially crafted SVG file.

EPSS

0.002

Percentile

57.9%

Related for VERACODE:33876