Loading HuntDB...

Stored XSS thru SVG upload

M
Moneybird
Submitted None

Team Summary

Official summary from Moneybird

Researcher found a way to add XSS code to SVG uploads in our software. We have improved our software by preventing SVG and HTML files to be presented in the webbrowser to prevent XSS attacks.

Reported by 4lemon

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Generic