Issue metadata
Sign in to add a comment
|
SVG XSS
Reported by
shubhamg...@gmail.com,
May 5 2016
|
||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.94 Safari/537.36 Steps to reproduce the problem: I don't know i have to report this bug here or not. I'm able to reproduce this xss on Chrome, Firefox and Opera. I have found a persistent xss vulnerability that allows attackers steal user's cookies, do csrf attacks against victim account or do phishing attacks. This vulnerability occurs due the page allows svg attachments that contains "xmlns=http://www.w3.org/1999/xhtml", then the page will render the content of the xml as html , so resulting on a xss vulnerability. <svg xmlns="http://www.w3.org/2000/svg" viewbox="-1 -1 15 15"> <rect y="0" height="13" width="12" stroke="#179" rx="1" fill="#2ac"/> <text x="1.5" y="11" font-family="courier" stroke="white" font-size="16"><![CDATA[B]]></text> <iframe xmlns="http://www.w3.org/1999/xhtml" srcdoc="<script>alert('XSSED => Domain('+top.document.domain+')');</script>"></iframe> </svg> kindly let me know if you needed more info. What is the expected behavior? What went wrong? Some web apps now allow svg files to be uploaded under images category. Did this work before? N/A Chrome version: 50.0.2661.94 Channel: stable OS Version: OS X 10.11.4 Flash Version: Shockwave Flash 21.0 r0 i reported this bug on hackerone internet bug bounty program they told me This is by-designed browser behavior. If you disagree, file a bug report with Mozilla or Chrome. Thanks! that's why i'm reporting this bug here. Best Regard Shubham
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||
Comment 1 by f...@chromium.org
, May 6 2016Status: WontFix (was: Unconfirmed)