VYPR

Packagist (Composer) package

mojo42/jirafeau

pkg:composer/mojo42/jirafeau

Vulnerabilities (1)

  • CVE-2022-30110May 17, 2022
    affected < 4.4.0fixed 4.4.0

    The file preview functionality in Jirafeau < 4.4.0, which is enabled by default, could be exploited for cross site scripting. An attacker could upload image/svg+xml files containing JavaScript. When someone visits the File Preview URL for this file, the JavaScript inside of this