Starter Templates through 4.2.1 registers an upload_mimes filter that permits SVG uploads, but never sanitizes the uploaded SVG contents. An authenticated attacker with contributor-level access or above could upload an SVG carrying arbitrary script, which then executes for any user who opens the file. The fix sanitizes SVG uploads on the... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
SOCIAL SHARE CARD GENERATOR