Is it possible to extend (let's say with an add-on) the image proxy to support different formats?I responded elsewhere that this is intentional - we only allow PNG, GIF, and JPEG and we do basic verification on them.
True, but so does any web page. If you follow a link to my website, JS will get executed. Would that be any different?The browser executes the JS if you visit the URL directly though, so it's still an XSS unfortunately...
http://www.tapper-ware.net/blog/?p=184.SVG most definitely has been an attack vector before -- GMail was bitten by it, for example (involved code running in their domain context).
We use essential cookies to make this site work, and optional cookies to enhance your experience.