Stored cross-site scripting via vulnerability dependency

Stored XSS vulnerability available due to insufficient SVG sanitization, it may be exploited if the uploaded SVG image is included in line in an HTML page.

This vulnerability affects the following application versions:

  • SVG Support 2.4
  • SVG Support 2.4.1
  • SVG Support 2.4.2
  • SVG Support 2.5
  • SVG Support 2.5.1
  • SVG Support 2.5.2
  • SVG Support 2.5.3
  • SVG Support 2.5.4
  • SVG Support 2.5.5
  • SVG Support 2.5.6
  • SVG Support 2.5.7
  • SVG Support 2.5.8

Authenticated (author+) stored cross-site scripting via svg file upload

Stored cross-site scripting vulnerability available via svg file uploads due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the svg file. By default, this can only be exploited by administrators, but the ability to upload svg files can be extended to authors.

This vulnerability affects the following application versions:

  • SVG Support 2.5.2
  • SVG Support 2.5.3
  • SVG Support 2.5.4
  • SVG Support 2.5.5
  • SVG Support 2.5.6
  • SVG Support 2.5.7
  • SVG Support 2.5.8
  • SVG Support 2.5.9
  • SVG Support 2.5.10

Cross-site scripting on SVG uploads and attachments.

Improved sanitization of SVG uploads and attachments enhances security by filtering out potentially harmful code while prevent vulnerabilities like XSS while ensuring safe handling of SVG files.

This vulnerability affects the following application versions:

  • SVG Support 2.3
  • SVG Support 2.3.1
  • SVG Support 2.3.2
  • SVG Support 2.3.3
  • SVG Support 2.3.4
  • SVG Support 2.3.5
  • SVG Support 2.3.6
  • SVG Support 2.3.7
  • SVG Support 2.3.8
  • SVG Support 2.3.9
  • SVG Support 2.3.10
  • SVG Support 2.3.11
  • SVG Support 2.3.12
  • SVG Support 2.3.13
  • SVG Support 2.3.14
  • SVG Support 2.3.15
  • SVG Support 2.3.16
  • SVG Support 2.3.17
  • SVG Support 2.3.18
  • SVG Support 2.3.19
  • SVG Support 2.3.20
  • SVG Support 2.3.21
  • SVG Support 2.4
  • SVG Support 2.4.1
  • SVG Support 2.4.2
  • SVG Support 2.5
  • SVG Support 2.5.1
  • SVG Support 2.5.2
  • SVG Support 2.5.3
  • SVG Support 2.5.4
  • SVG Support 2.5.5
  • SVG Support 2.5.6
  • SVG Support 2.5.7