CVE-2019-10772
11.12.2019, 16:15
It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the xlink namespace by the sanitizer.
Vendor | Product | Version |
---|---|---|
svg-sanitizer_project | svg-sanitizer | 𝑥 < 0.13.1 |
𝑥
= Vulnerable software versions