Vulnerability Details CVE-2019-18856
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-18856
-
cpe:2.3:a:drupal:svg_sanitizer:7.x-1.0
-
cpe:2.3:a:drupal:svg_sanitizer:7.x-1.1
-
cpe:2.3:a:drupal:svg_sanitizer:7.x-1.2
-
cpe:2.3:a:drupal:svg_sanitizer:7.x-1.3
-
cpe:2.3:a:drupal:svg_sanitizer:7.x-1.4
-
cpe:2.3:a:drupal:svg_sanitizer:7.x-1.5
-
cpe:2.3:a:drupal:svg_sanitizer:8.x-1.0