Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-9516 - Vulnerability Database

Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-9516

Medium
Reference: CVE-2017-9516
Title: Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.