A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
2019-11-11T15:15:12.467
2024-11-21T04:33:43.443
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | drupal | svg_sanitizer | ≤ 7.x-1.5 | Yes |
Application | drupal | svg_sanitizer | 8.x-1.0 | Yes |