Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35960
HistoryJun 13, 2022 - 8:03 a.m.

Arbitrary Code Injection

2022-06-1308:03:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
arbitrary code injection
svg element
file system
png file
software

EPSS

0.001

Percentile

50.3%

convert-svg-core is vulnerable to arbitrary code injection. The vulnerability exists because the library does not properly remove the malicious attributes from the SVG element before being rendered, allowing an attacker to read files from the file system and show the file content as a PNG file by providing a maliciously crafted SVG file.

EPSS

0.001

Percentile

50.3%

Related for VERACODE:35960