Namespace Bypass Vulnerability in Enshrined SVG Sanitizer for PHP
CVE-2019-10772

6.1MEDIUM

Key Information:

Vendor
CVE Published:
11 December 2019

What is CVE-2019-10772?

A vulnerability exists in the Enshrined SVG Sanitizer for PHP that allows for a bypass of security measures through improper handling of the xlink namespace. This flaw can be exploited via the 'xlink:href' attribute, enabling malicious users to inject harmful SVG content, potentially leading to security risks for applications utilizing affected versions of the sanitizer. Developers are urged to update to version 0.13.1 or later to mitigate this risk.

Affected Version(s)

enshrined/svg-sanitize All versions prior to version 0.13.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.