Headline
CVE-2022-32115: Known: social publishing for groups and individuals
An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file.
Simple publishing
Known allows you to create and share photos, notes, stories, songs, and more. It’s easy to use and its web interface works on any device.
Features at a glance
Bookmarklet
Easily post to your site, save links, and respond to comments from any page on the web
#Tags
Use hashtags with any content to categorize and organize what you publish
Responsive Layout
View, edit, and post to your site from any device
Decentralized Indieweb
Sites can respond to each other, bookmark each others’ content and leave comments on each others’ posts
Email Notifications
Get updated whenever someone responds to a post
Feeds
Get your latest updates via RSS, XML, JSON, or KML
Multi-Author
Invite an unlimited number of collaborators and create a multi-user site
HTML & Rich Text Editor
Handcraft your posts in HTML or save time with the WYSIWYG
Custom URL
Bring your own URL and really own your site with a custom domain
Static Pages
Round out your site with static content like an about page or a contact page
Privacy
Keep your site private and create a space for your personal thoughts or a private group discussion
Custom JavaScript & CSS
Change your site’s look and add your own analytics with JavaScript and CSS editors
Any device, any place
You already spend enough time in front of a computer, and inspiration can strike anywhere. Known is fully responsive and works on whatever device you’ve got in your hand. Whether you’re sharing a sunset picture from the beach or blogging from the road, Known is there for you.
“more easily organize all your digital info in one place”
“designed to give everyone a fully open publishing platform”
“This is really how the web should be.”
Related news
An issue in the isSVG() function of Known v1.3.1 allows attackers to execute arbitrary code via a crafted SVG file. The researcher report indicates that versions 1.3.1 and prior are vulnerable. Version 1.2.2 is the last version tagged on GitHub and in Packagist, and development related to the 1.3.x branch is currently on the `dev` branch of the idno/known repository.