CVE-2019-18857
11.11.2019, 15:15
darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript	:alert substring.
Vendor | Product | Version |
---|---|---|
svg-sanitizer_project | svg-sanitizer | 𝑥 < 0.12.0 |
𝑥
= Vulnerable software versions
References