Stored cross-site scripting via vulnerability dependency
Stored XSS vulnerability available due to insufficient SVG sanitization, it may be exploited if the uploaded SVG image is included in line in an HTML page.
This vulnerability affects the following application versions:
- SVG Support 2.4
- SVG Support 2.4.1
- SVG Support 2.4.2
- SVG Support 2.5
- SVG Support 2.5.1
- SVG Support 2.5.2
- SVG Support 2.5.3
- SVG Support 2.5.4
- SVG Support 2.5.5
- SVG Support 2.5.6
- SVG Support 2.5.7
- SVG Support 2.5.8