Svg Image - Critical - Cross site scripting - SA-CONTRIB-2020-008
Project: Svg Image
Date: 2020-March-25
Security risk: Critical 15∕25
Vulnerability: Cross site scripting
Description
SVG Image module allows to upload SVG files.
The module did not sufficiently protect against malicious code inside SVG files leading to a Cross Site Scripting vulnerability.
This vulnerability is mitigated by the fact that an attacker must have permission to upload an SVG file.
Solution
Install the latest version:
If you use the SVG Image module for Drupal 8.x, upgrade to Svg Image 8.x-1.10
Also see the Svg Image project page.
We value your opinion. Please add your feedback.