Uploaded image for project: 'Hippo CMS'
  1. Hippo CMS
  2. CMS-14278

It is possible to perform a XSS attack by an uploaded svg image file

    XMLWordPrintable

Details

    • Bug
    • Status: Closed
    • Normal
    • Resolution: Fixed
    • None
    • 12.6.15, 13.4.8, 14.5.0
    • None
    • None
    • 0.25
    • Quasar
    • Puma Sprint 249, Puma Sprint 250

    Description

       

      Reproduction (with saas sample project, but any project will do):

      Expect: svg shown with no alert popup

      Actual: alert popup displayed.

      Solution: Prevent XSS attacks via onload attribute of svg images by removing it from uploaded svg files.

       

       

      Attachments

        Activity

          People

            Unassigned Unassigned
            meggermont Michiel Eggermont (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: