Description
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2014-6538 Vulnerability (CVE-2014-6538)
IBM WebSEAL Incorrect Authorization Vulnerability (CVE-2023-38368)
WordPress Plugin Sendit WP Newsletter 'id' Parameter SQL Injection (2.1.0)
WordPress Plugin YITH WooCommerce Advanced Reviews Security Bypass (1.3.9)
WordPress Plugin Quick Featured Images Cross-Site Scripting (12.3.5)