Closed maudov closed 3 years ago
Thanks @maudov, I will fix it as soon a possible!
Hi @maudov, the security problem should now be fixed. I've opted for removing javascripts from the svg diagram, because working with base64 was causing some issue when the diagram was re-edited before reloading the page. Thanks again for reporting it.
Hi @mikitex70, thank you for your fast reaction, unfortunately there are many ways to bypass the fix (i.e : Githubissues.
Hi,
SVG's rendering is prone to XSS in redmine_drawio. steps to reproduce :
upload an SVG containing a script to a wiki page and attach it ( {{drawio_attach(...)}})