XSS in enshrined/svg-sanitize due to mishandled script and data values in attributes
High severity
GitHub Reviewed
Published
Jan 8, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jan 8, 2020
Published to the GitHub Advisory Database
Jan 8, 2020
Last updated
Jan 9, 2023
enshrined/svg-sanitize before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript :alert substring.
References