Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SVGO: removeScripts plugin leaves some executable scripts intact
Vulnerability Description
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as <svg:script> and, in versions 3 and 4, matches JavaScript URIs case sensitively. Applications that process untrusted SVG input with this plugin enabled and serve the result can allow scripts to execute when another user opens the SVG, exposing local storage or cookies. This issue is fixed in versions 2.8.3, 3.3.4, and 4.0.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
svg SVGO 跨站脚本漏洞
Vulnerability Description
SVGO是svg组织开源的一款优化SVG图形的命令行工具。 svg SVGO 1.0.0至2.8.3之前版本、3.0.0至3.3.4之前版本和4.0.0至4.0.2之前版本存在安全漏洞,该漏洞源于removeScripts插件未移除命名空间或带前缀的脚本元素(如<svg:script>),且在版本3和4中对JavaScript URI匹配区分大小写,可能导致其他用户打开SVG时脚本执行,暴露本地存储或Cookie。
CVSS Information
N/A
Vulnerability Type
N/A