Description
svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document.
Remediation
References
https://github.com/domenic/svg2png/issues/117
Related Vulnerabilities
CVE-2022-25885 Vulnerability in npm package muhammara
CVE-2017-3208 Vulnerability in maven package com.exadel.flamingo.flex:amf-serializer
CVE-2020-36380 Vulnerability in npm package aaptjs
CVE-2020-7792 Vulnerability in maven package org.webjars.npm:mout
CVE-2020-2185 Vulnerability in maven package org.jenkins-ci.plugins:ec2