Skip to content

Cross Site Scripting (XSS) #2869

Closed Answered by maudetes
gpsilv4 asked this question in Q&A
Discussion options

You must be logged in to vote

Thank you for this report! We do not render the SVG file uploaded on data.gouv.fr, thus preventing loading the malicious code, and preventing the attack from being executed.
However, we should indeed take appropriate measures to prevent any potential security vulnerabilities, probably by implementing input validation on SVG files. It would make sure to prevent being a vector of malicious content.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by maudetes
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants