Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Bypassing Firefox's HTML Sanitizer API

Summary

Gareth Heyes bypassed Firefox's HTML Sanitizer API: SVG 'use' elements importing same-origin absolute URLs still executed JavaScript, even for uploads protected with Content-Disposition: attachment.
Published
Collected

original ↗

Related coverage

back