Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/getgrav/grav/issues/2657 | third party advisory exploit |