Other nomination
Code Vulnerabilities Put Skiff Emails at Riskr
Skiff's webmail inserted a div into the already-sanitized DOM inside an svg element; because a div is not a valid svg child, re-serializing and re-parsing the HTML moved the style element out of SVG context, so an img onerror hidden in an attribute came alive, a mutation XSS past DOMPurify.
Record
- Researcher
- Paul Gerste
- Date
In the archive
Related sources
- Part 1: Proton Mail
- Presentation of the email-security research series
- Foundational CSP-bypass demonstration
Tags
This page is the archive's own catalogue record. The research is the work of Paul Gerste, first published at the original source. Preserved copies are kept so the citation survives its host.