Description
svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document.
Remediation
References
https://github.com/domenic/svg2png/issues/117
Related Vulnerabilities
CVE-2012-5784 Vulnerability in maven package org.apache.axis:axis
CVE-2022-25940 Vulnerability in maven package org.webjars.npm:lite-server
CVE-2022-0239 Vulnerability in maven package edu.stanford.nlp:stanford-corenlp
CVE-2018-1000536 Vulnerability in npm package medis
CVE-2015-1833 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-webdav