CVE-2022-24278
10.06.2022, 20:15
The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.
Vendor | Product | Version |
---|---|---|
convert-svg_project | convert-svg | 𝑥 < 0.6.4 |
𝑥
= Vulnerable software versions
References