build1 publisher
An <object> tag turns an uploaded SVG into stored XSS for every visitor
OopsSec Store, a deliberately vulnerable Next.js app, lets an admin-uploaded SVG run JavaScript in every visitor's browser. It works because the server trusts the client-set Content-Type and the product page renders SVGs through an <object> tag.
Publishers:dev.to
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives40
- Confidence72