[wp-trac] [WordPress Trac] #24251: Reconsider SVG inclusion to get_allowed_mime_types

WordPress Trac noreply at wordpress.org
Fri Mar 17 00:17:37 UTC 2023


#24251: Reconsider SVG inclusion to get_allowed_mime_types
-------------------------------+------------------------------
 Reporter:  JustinSainton      |       Owner:  (none)
     Type:  enhancement        |      Status:  reopened
 Priority:  normal             |   Milestone:  Awaiting Review
Component:  Upload             |     Version:
 Severity:  normal             |  Resolution:
 Keywords:  early 2nd-opinion  |     Focuses:
-------------------------------+------------------------------

Comment (by shamank):

 OMG I can't believe this is still considered a security concern after 10
 years! I realize common sense was never part of this and it won't never be
 in the future either. I have a new security meassure to suggest! Can we
 also block CSS? I'm worried about CSS exploits:
 https://book.hacktricks.xyz/pentesting-web/xs-search/css-injection Is
 there any protection we can use to prevent them? Maybe a DISABLE_CSS flag
 or just disabling it by default and let the user install an external
 plugin to enable it under their risk? My GOD...

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/24251#comment:102>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list