RSS   Podatności dla 'Scratch-svg-renderer'   RSS

2020-10-21
 
CVE-2020-7750

CWE-79
 

 
This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.

 


Copyright 2021, cxsecurity.com

 

Back to Top