Loading HuntDB...

READ .svg files by changing .svg into .png extension

I
Instacart
Submitted None
Reported by codertom

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
Good Day, Instacart In list and recipe we could see that we can upload a picture . It won't accept `.svg` files but by changing it to `.png`. ###Steps to Reproduce 1. Create a list and recipe under accounts 2. Upload a picture. We will upload an `svg` but with a `png` extension. I've attached an `svg` file please open it and save it as `file.png` 3. Now upload the photo and you will then now see that the svg we have made is reflected in the background photo area. Regards, TOM

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Violation of Secure Design Principles