Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35955
HistoryJun 13, 2022 - 5:39 a.m.

Directory Traversal

2022-06-1305:39:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
directory traversal
svg tags
file directories

EPSS

0.002

Percentile

56.1%

convert-svg-core is vulnerable to directory traversal. The vulnerability exists in Converter.js because the SVG tags are not properly sanitized which allows an attacker to access file directories via a specially crafted SVG file.

EPSS

0.002

Percentile

56.1%

Related for VERACODE:35955