Cross-Site Scripting Vulnerability in svg-sanitizer Library

Cross-Site Scripting Vulnerability in svg-sanitizer Library

CVE-2022-23638 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no workaround available.

Learn more about our User Device Pen Test.