Description
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
Remediation
References
Related Vulnerabilities
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2022-25763)
WordPress Plugin Contact Form by Supsystic Cross-Site Scripting (1.7.14)
WordPress Plugin Integration for Contact Form 7 and Zoho Cross-Site Scripting (1.1.7)
WordPress Plugin WordPress Shortcodes-Shortcodes Ultimate Remote Code Execution (5.0.0)