Hacking Hacker Noon: Cross-Site Scripting attacks via crafted SVG images

How can malicious SVGs be used to exploit XSS vulnerabilities?

Ax Sharma
AxDB
Published in
6 min readJan 18, 2020

--

Hacker Noon profile section

My colleague, Mike and I while pondering usual work stuff, began to casually discuss the potential of SVGs, especially how cool is that they are mere XML documents represented as an image — enabling them to act as the perfect latent

--

--