Collected research
Code Vulnerabilities Put Skiff Emails at Riskr
Code Vulnerabilities Put Skiff Emails at Risk
Skiff's webmail inserted a div into the already-sanitized DOM inside an svg element; because a div is not a valid svg child, re-serializing and re-parsing the HTML moved the style element out of SVG context, so an img onerror hidden in an attribute came alive, a mutation XSS past DOMPurify.
Record
- Document
- Code Vulnerabilities Put Skiff Emails at Risk
- Researcher
- Paul Gerste
- Published by
- sonarsource.com
- Date
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Paul Gerste, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .