The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at all. Albeit the markup is not valid it still is evaluated in browsers and leads to cross-site scripting. This is fixed in version 1.0.3.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2020-05-13T18:40:11

Updated: 2024-08-04T11:21:14.616Z

Reserved: 2020-03-30T00:00:00

Link: CVE-2020-11070

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-05-13T19:15:11.597

Modified: 2020-05-15T13:43:28.503

Link: CVE-2020-11070

cve-icon Redhat

No data.