Svg Image - Critical - Cross site scripting - SA-CONTRIB-2020-008
Project: Svg Image
Security risk: Critical 15∕25
Vulnerability: Cross site scripting
SVG Image module allows to upload SVG files.
The module did not sufficiently protect against malicious code inside SVG files leading to a Cross Site Scripting vulnerability.
This vulnerability is mitigated by the fact that an attacker must have permission to upload an SVG file.
Install the latest version: