MEDIUM
Safe SVG < 1.9.10 - SVG Sanitisation Bypass
Published Apr 18, 2022
6.1
MEDIUMCVSS 3.1
EPSS 1.20%
Description
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks).
Affected products
- Vendor n/a Product Safe SVG Defaultn/a
- Version 1.9.10StatusaffectedConstraints<1.9.10
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Safe SVG | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1635 Advisory
- https://github.com/10up/safe-svg/commit/00cb9a86d1bff2214714557d1901ec3896564e50
- https://github.com/10up/safe-svg/pull/28 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/advisories/GHSA-5h7w-hmxc-99g5 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1091
- https://wpscan.com/vulnerability/4d12533e-bdb7-411f-bcdf-4c5046db13f3 x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1635 | Advisory | |
| https://github.com/10up/safe-svg/commit/00cb9a86d1bff2214714557d1901ec3896564e50 | ||
| https://github.com/10up/safe-svg/pull/28 | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://github.com/advisories/GHSA-5h7w-hmxc-99g5 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1091 | ||
| https://wpscan.com/vulnerability/4d12533e-bdb7-411f-bcdf-4c5046db13f3 | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Apr 18, 2022
Updated Aug 2, 2024
Reserved Mar 25, 2022
Link CVE-2022-1091
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-1635 GHSA-5H7W-HMXC-99G5 Assigner WPScan
Published Apr 18, 2022
Updated Aug 2, 2024
Exploited since n/a
Link EUVD-2022-1635