CVE-2022-1091: Safe SVG < 1.9.10 - SVG Sanitisation Bypass
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerability, an attacker will be able to perform the kinds of attacks that this plugin should prevent (mainly XSS, but depending on further use of uploaded SVG files potentially other XML attacks).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1091?
CVE-2022-1091 has been classified as a medium severity vulnerability due to its potential to allow XSS attacks by bypassing file upload restrictions.
How do I fix CVE-2022-1091?
To fix CVE-2022-1091, you should update the Safe SVG plugin to version 1.9.10 or later.
What systems are affected by CVE-2022-1091?
CVE-2022-1091 affects versions of the Safe SVG WordPress plugin prior to 1.9.10.
What attacks can CVE-2022-1091 facilitate?
CVE-2022-1091 can facilitate XSS (Cross-Site Scripting) attacks if exploited.
How is CVE-2022-1091 exploited?
CVE-2022-1091 can be exploited by spoofing the content-type in the POST request during file uploads.