SVG with embedded scripts can lead to cross-site scripting attacks in xml2rfc
Moderate severity
GitHub Reviewed
Published
Apr 12, 2022
in
ietf-tools/xml2rfc
•
Updated Jan 11, 2023
Description
Published to the GitHub Advisory Database
Apr 22, 2022
Reviewed
Apr 22, 2022
Last updated
Jan 11, 2023
xml2rfc allows
script
elements in SVG sources.In HTML output having these script elements can lead to XSS attacks.
Sample XML snippet:
Impact
This vulnerability impacts website that publish HTML drafts and RFCs.
Patches
This has been fixed in version 3.12.4.
Workarounds
If SVG source is self-contained within the XML, scraping
script
elements from SVG files.References
For more information
If you have any questions or comments about this advisory:
References