GHSA-ffq7-898w-9jc4: DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
A user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user.
References
Code Behaviors & Features
Detect and mitigate GHSA-ffq7-898w-9jc4 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →