VYPR
Unrated severityNVD Advisory· Published Dec 12, 2023· Updated Aug 2, 2024

php-svg-lib unsafe attributes merge when parsing `use` tag

CVE-2023-50252

Description

php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling ` tag that references an tag, it merges the attributes from the tag to the tag. The problem pops up especially when the href attribute from the ` tag has not been sanitized. This can lead to an unsafe file read that can cause PHAR Deserialization vulnerability in PHP prior to version 8. Version 0.5.1 contains a patch for this issue.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.