The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at all. Albeit the markup is not valid it still is evaluated in browsers and leads to cross-site scripting. This is fixed in version 1.0.3.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2020-05-13T18:40:11

Updated: 2020-05-13T18:40:11

Reserved: 2020-03-30T00:00:00


Link: CVE-2020-11070

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-05-13T19:15:11.597

Modified: 2020-05-15T13:43:28.503


Link: CVE-2020-11070

JSON object: View

cve-icon Redhat Information

No data.

CWE