Menu

#Funcdef

4 posts

Feed·
4 of 4 posts
The woes of sanitizing SVGs
📰
0

The woes of sanitizing SVGs

muffin.ink·@HashtagPLUS·about 1 month ago
#a2RZg5Ax
#example#node#non#safe_url#funcdef#scratch

Scratch has a long history of SVG-related vulnerabilities. The source of these is that Scratch parses user-generated (ie. attacker-controlled) content into an element and appends it into the main document for various operations (eg.…

15s
Read More