Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36477
HistoryJul 25, 2022 - 11:28 a.m.

Remote Code Execution

2022-07-2511:28:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
25
svg vulnerability
remote attackers
malicious payloads
sanitization
software vulnerability

EPSS

0.071

Percentile

94.0%

convert-svg-core is vulnerable to remote code execution. Lack of proper sanitization allows remote attackers to upload and execute malicious payloads on the system under attack via a crafted SVG file.

EPSS

0.071

Percentile

94.0%

Related for VERACODE:36477