CVE-2020-7750

This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.6 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
snykCNA
9.6 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
mitscratch-svg-renderer
0.1.0
mitscratch-svg-renderer
0.1.0:prerelease1515799461
mitscratch-svg-renderer
0.1.0:prerelease1515800444
mitscratch-svg-renderer
0.1.0:prerelease20180117145116
mitscratch-svg-renderer
0.1.0:prerelease20180117210827
mitscratch-svg-renderer
0.1.0:prerelease20180118201049
mitscratch-svg-renderer
0.1.0:prerelease20180118201241
mitscratch-svg-renderer
0.1.0:prerelease20180118224509
mitscratch-svg-renderer
0.1.0:prerelease20180124043252
mitscratch-svg-renderer
0.1.0:prerelease20180124054052
mitscratch-svg-renderer
0.1.0:prerelease20180210005926
mitscratch-svg-renderer
0.1.0:prerelease20180329174139
mitscratch-svg-renderer
0.1.0:prerelease20180423193917
mitscratch-svg-renderer
0.1.0:prerelease20180508170432
mitscratch-svg-renderer
0.1.0:prerelease20180510171850
mitscratch-svg-renderer
0.1.0:prerelease20180510181711
mitscratch-svg-renderer
0.1.0:prerelease20180511144653
mitscratch-svg-renderer
0.1.0:prerelease20180514170126
mitscratch-svg-renderer
0.1.0:prerelease20180521194642
mitscratch-svg-renderer
0.1.0:prerelease20180524204036
mitscratch-svg-renderer
0.1.0:prerelease20180524210316
mitscratch-svg-renderer
0.1.0:prerelease20180531205843
mitscratch-svg-renderer
0.1.0:prerelease20180531214630
mitscratch-svg-renderer
0.1.0:prerelease20180605140533
mitscratch-svg-renderer
0.2.0:prerelease20180605154326
mitscratch-svg-renderer
0.2.0:prerelease20180607141644
mitscratch-svg-renderer
0.2.0:prerelease20180613184320
mitscratch-svg-renderer
0.2.0:prerelease20180618172917
mitscratch-svg-renderer
0.2.0:prerelease20180711180400
mitscratch-svg-renderer
0.2.0:prerelease20180712223402
mitscratch-svg-renderer
0.2.0:prerelease20180817005452
mitscratch-svg-renderer
0.2.0:prerelease20180821210632
mitscratch-svg-renderer
0.2.0:prerelease20180907141232
mitscratch-svg-renderer
0.2.0:prerelease20180926143036
mitscratch-svg-renderer
0.2.0:prerelease20181017193458
mitscratch-svg-renderer
0.2.0:prerelease20181024192149
mitscratch-svg-renderer
0.2.0:prerelease20181101210634
mitscratch-svg-renderer
0.2.0:prerelease20181126212715
mitscratch-svg-renderer
0.2.0:prerelease20181212190400
mitscratch-svg-renderer
0.2.0:prerelease20181212222326
mitscratch-svg-renderer
0.2.0:prerelease20181212230607
mitscratch-svg-renderer
0.2.0:prerelease20181213165142
mitscratch-svg-renderer
0.2.0:prerelease20181213192400
mitscratch-svg-renderer
0.2.0:prerelease20181218153528
mitscratch-svg-renderer
0.2.0:prerelease20181220183040
mitscratch-svg-renderer
0.2.0:prerelease20190109201344
mitscratch-svg-renderer
0.2.0:prerelease20190110205335
mitscratch-svg-renderer
0.2.0:prerelease20190125192231
mitscratch-svg-renderer
0.2.0:prerelease20190304180800
mitscratch-svg-renderer
0.2.0:prerelease20190329052730
mitscratch-svg-renderer
0.2.0:prerelease20190419183947
mitscratch-svg-renderer
0.2.0:prerelease20190521170426
mitscratch-svg-renderer
0.2.0:prerelease20190523193400
mitscratch-svg-renderer
0.2.0:prerelease20190715144718
mitscratch-svg-renderer
0.2.0:prerelease20190715153806
mitscratch-svg-renderer
0.2.0:prerelease20190820171249
mitscratch-svg-renderer
0.2.0:prerelease20190822193232
mitscratch-svg-renderer
0.2.0:prerelease20190822202608
mitscratch-svg-renderer
0.2.0:prerelease20191031221353
mitscratch-svg-renderer
0.2.0:prerelease20191104164753
mitscratch-svg-renderer
0.2.0:prerelease20191217211338
mitscratch-svg-renderer
0.2.0:prerelease20200103191258
mitscratch-svg-renderer
0.2.0:prerelease20200103211543
mitscratch-svg-renderer
0.2.0:prerelease20200109070519
mitscratch-svg-renderer
0.2.0:prerelease20200205003215
mitscratch-svg-renderer
0.2.0:prerelease20200205003400
mitscratch-svg-renderer
0.2.0:prerelease20200507183648
mitscratch-svg-renderer
0.2.0:prerelease20200604203226
mitscratch-svg-renderer
0.2.0:prerelease20200609210443
mitscratch-svg-renderer
0.2.0:prerelease20200610220938
mitscratch-svg-renderer
0.2.0:prerelease20201008203328
mitscratch-svg-renderer
0.2.0:prerelease20201009194722
mitscratch-svg-renderer
0.2.0:prerelease20201009195807
mitscratch-svg-renderer
0.2.0:prerelease20201009202925
mitscratch-svg-renderer
0.2.0:prerelease20201009211507
mitscratch-svg-renderer
0.2.0:prerelease20201011114003
mitscratch-svg-renderer
0.2.0:prerelease20201012151417
mitscratch-svg-renderer
0.2.0:prerelease20201013123302
mitscratch-svg-renderer
0.2.0:prerelease20201013184332
mitscratch-svg-renderer
0.2.0:prerelease20201014105708
mitscratch-svg-renderer
0.2.0:prerelease20201014130133
mitscratch-svg-renderer
0.2.0:prerelease20201014145347
mitscratch-svg-renderer
0.2.0:prerelease20201015122106
mitscratch-svg-renderer
0.2.0:prerelease20201015135047
mitscratch-svg-renderer
0.2.0:prerelease20201015194358
mitscratch-svg-renderer
0.2.0:prerelease20201016121710
𝑥
= Vulnerable software versions