Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SVG Salamander 安全漏洞
Vulnerability Description
SVG Salamander是一款轻量级的用于Java的SVG渲染器和动画引擎。 Web应用程序中使用的SVG Salamander库中存在安全漏洞。远程攻击者可借助SVG文件中的xlink:href属性利用该漏洞实施服务器端请求伪造攻击。
CVSS Information
N/A
Vulnerability Type
N/A