Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39881
HistoryMar 21, 2023 - 2:24 a.m.

Cross-site Scripting (XSS)

2023-03-2102:24:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
cross-site scripting
svg
sanitizer
vulnerability
html elements
attack

enshrined/svg-sanitize is vulnerable to Cross-site Scripting (XSS). The vulnerability exists because the cleanUnsafeNodes function in Sanitizer.php does not properly sanitize the HTML elements within CDATA, which allows an attacker to launch an XSS attack with the unsafe SVG file.