← back
CVE-2022-1091

Safe SVG < 1.9.10 - SVG Sanitisation Bypass

EPSS 1.2%CWE-79
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
18 Apr 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks).
Affected products
Unknown · Safe SVG

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →