DRUPAL-CONTRIB-2024-050

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/svg_embed/DRUPAL-CONTRIB-2024-050.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2024-050
Aliases
  • CVE-2024-13286
Published
2024-10-23T12:09:48Z
Modified
2025-12-10T23:41:24.565019Z
Summary
[none]
Details

This module enables you to embed the content of an SVG file into the body html of a node and optionally allows to translate text contained within the image.

The module doesn't sufficiently sanitize the SVG file before embedding it into the html.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to upload SVG files, and the permission to use a text format that includes the SVG embed filter.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/svg_embed

Package

Name
drupal/svg_embed
Purl
pkg:composer/drupal/svg_embed

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.2
Database specific
{
    "constraint": "<2.1.2"
}

Database specific

affected_versions
"<2.1.2"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/svg_embed/DRUPAL-CONTRIB-2024-050.json"