XSS Vulnerability via uploading html and svg files #8302
Labels
Customer reported Bug
Support Ticket and Customer reported bugs
Paid
This label considered as a Paid Product issues.
Link: https://github.com/Asadiqbal2
Description:
Issue - XSS code placed in html and svg format files can be uploaded, attached and thereby executable after ticket is created and the attachment is clicked open.
Details and steps to reproduce given in below document
XSS.Via.File.Upload.pdf
Steps To Reproduce:
Screenshots:
Sample html file can be crated with following xss code
<script>window.location.href="https://evil.com"</script>The text was updated successfully, but these errors were encountered: