CVE-2023-49146
22.11.2023, 22:15
DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.
Vendor | Product | Version |
---|---|---|
getgrav | dom-sanitizer | 𝑥 < 1.0.7 |
𝑥
= Vulnerable software versions
References