Safety vulnerability ID: 61345
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Plone.namedfile 5.6.1, 6.0.3, 6.1.3 and 6.2.1 include a fix for CVE-2023-41048: Stored Cross Site Scripting with SVG images.
https://github.com/plone/plone.namedfile/security/advisories/GHSA-jj7c-jrv4-c65x
Latest version: 6.3.1
File types and fields for images, files and blob files with filenames
------------------
Bug fixes:
- Fix stored XSS (Cross Site Scripting) for SVG images.
Done by forcing a download instead of displaying inline.
See `security advisory <https://github.com/plone/plone.namedfile/security/advisories/GHSA-jj7c-jrv4-c65x>`_.
[maurits] (1)
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application