Stored XSS thru SVG upload
M
Moneybird
Submitted None
Team Summary
Official summary from Moneybird
Researcher found a way to add XSS code to SVG uploads in our software. We have improved our software by preventing SVG and HTML files to be presented in the webbrowser to prevent XSS attacks.
Actions:
Reported by
4lemon
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic