Menu

#Non

2 posts

Feed·
2 of 2 posts
The woes of sanitizing SVGs
📰
0

The woes of sanitizing SVGs

muffin.ink·@HashtagPLUS·about 1 month ago
#a2RZg5Ax
#example#node#non#safe_url#funcdef#scratch

Scratch has a long history of SVG-related vulnerabilities. The source of these is that Scratch parses user-generated (ie. attacker-controlled) content into an element and appends it into the main document for various operations (eg.…

15s
Read More