Description
svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document.
Remediation
References
https://github.com/domenic/svg2png/issues/117
Related Vulnerabilities
CVE-2023-45303 Vulnerability in maven package org.thingsboard:thingsboard
CVE-2020-14359 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2021-32573 Vulnerability in npm package express-cart
CVE-2021-27405 Vulnerability in npm package @progfay/scrapbox-parser
CVE-2022-36033 Vulnerability in maven package org.jsoup:jsoup