9.6
CVSSv3

CVE-2020-7750

Published: 21/10/2020 Updated: 02/12/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.6 | Impact Score: 6 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

This affects the package scratch-svg-renderer prior to 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mit scratch-svg-renderer 0.1.0

mit scratch-svg-renderer 0.2.0

Exploits

Scratch Desktop version 317 suffers from code execution and cross site scripting vulnerabilities ...