GHSA-5jgj-h9wp-53fr, CVE-2022-32115
packagist/idno/known
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file.
All versions up to 1.3.1
Unfortunately, there is no solution available yet.
2022-07-26
source |