-
Persistent XSS enabled Persistent XSS in /api/1/datasets/xxxx/upload |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Thank you for this report! We do not render the SVG file uploaded on data.gouv.fr, thus preventing loading the malicious code, and preventing the attack from being executed. |
Beta Was this translation helpful? Give feedback.
Thank you for this report! We do not render the SVG file uploaded on data.gouv.fr, thus preventing loading the malicious code, and preventing the attack from being executed.
However, we should indeed take appropriate measures to prevent any potential security vulnerabilities, probably by implementing input validation on SVG files. It would make sure to prevent being a vector of malicious content.