plank/laravel-mediable is vulnerable to Stored Cross-Site Scripting (XSS)
61
Medium Risk
MediaUploader::upload() and replace() store uploaded SVG files without sanitizing their contents. An SVG containing an onload handler, <script> tag, or foreignObject element is written to disk unchanged and runs in the browser when a victim opens or previews it, so the script can capture session cookies and CSRF tokens. The fix adds a pluggable sanitizer pipeline and strips executable content from SVG uploads by default through enshrined/svg-sanitize.
You are affected if you are using a version that falls within the vulnerable range and you allow users to upload SVG files that are later opened or previewed in a browser.
plank/laravel-mediable is vulnerable to Stored Cross-Site Scripting (XSS) in versions 0.0.1 - 6.5.0.
Upgrade the plank/laravel-mediable library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.