CVE-2020-11070
Last modified
CVE-2020-11070 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at all. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at all. Albeit the markup is not valid it still is evaluated in browsers and leads to cross-site scripting. This is fixed in version 1.0.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Typo3 | Svg Sanitizer | < 1.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-11070?
How severe is CVE-2020-11070?
How do I fix CVE-2020-11070?
Are you affected by CVE-2020-11070?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
