DRUPAL-CONTRIB-2018-027

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/svg_formatter/DRUPAL-CONTRIB-2018-027.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2018-027
Published
2018-05-09T20:28:16Z
Modified
2025-12-10T23:30:55.750015Z
Summary
[none]
Details

This module adds a new formatter for the file fields, which allows any file extension to be uploaded.
The module doesn't sufficiently handle sanitization under the scenario uploaded SVG files.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission create or edit on certain content types that allows SVG files to be uploaded.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/svg_formatter

Package

Name
drupal/svg_formatter
Purl
pkg:composer/drupal/svg_formatter

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.0
Database specific
{
    "constraint": "<1.6.0"
}

Database specific

source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/svg_formatter/DRUPAL-CONTRIB-2018-027.json"
affected_versions
"<1.6.0"