new4시간 전· 1 sources
I uploaded a green square to a Next.js store and got stored XSS
Why it matters
Upload a malicious SVG to the admin product image field and get stored XSS that fires for every visitor. The admin panel in OopsSec Store lets you upload product images, including SVGs. Since SVG is j...
1
Sources
+1
24h
—
Growth
1d
Active