CVE-2023-50252

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 12, 2023
Updated: Dec 15, 2023
CWE ID 15
CWE ID 502

Summary

CVE-2023-50252 is a vulnerability affecting the php-svg-lib library before version 0.5.1. The issue lies in the handling of `<use>` tags that reference `<image>` tags. When these tags are merged, unsanitized attributes from the `<use>` tag, specifically the `href` attribute, can lead to an unsafe file read. This can result in a PHAR Deserialization vulnerability in PHP versions prior to 8. The vulnerability is resolved in version 0.5.1 with a patch.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share