savg-sanitizer 是一个用于清理 SVG/XML 内容的 PHP 库。在 1.0.0 版本之前,svg-sanitizer 存在一个安全漏洞:攻击者可以构造一个包含 属性默认值的恶意 SVG DTD,从而在 中的 函数中对同一属性名触发两次 调用。第一次删除会移除显式定义的属性,而 DTD 中定义的默认值会在该属性被删除后重新生成;当 安全检查路径执行第二次删除操作时,会导致 libxml 内部状态损坏,进而使 PHP 工作进程终止。攻击者若能够向漏洞清理接口提交恶意 SVG 内容,即可反复中断 PHP
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| darylldoyle | svg-sanitizer | < 1.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| darylldoyle | svg-sanitizer | < 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet