Open
Bug 1399507
Opened 7 years ago
Updated 2 years ago
The source of an <img> html element should only load valid image formats.
Categories
(Core :: Layout: Images, Video, and HTML Frames, defect, P3)
Tracking
()
UNCONFIRMED
People
(Reporter: jm.acuna73, Unassigned)
Details
User Agent: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.79 Safari/537.36
Steps to reproduce:
Go to:
data:text/html,<img src="https://feeds.feedburner.com/GoogleInbox"/>
Actual results:
The image executes the windows authentication dialog
Updated•7 years ago
|
Component: Untriaged → Layout: Images
Product: Firefox → Core
Updated•7 years ago
|
Priority: -- → P3
Updated•7 years ago
|
status-firefox57:
--- → wontfix
status-firefox58:
--- → fix-optional
Comment 1•7 years ago
|
||
status-firefox59:
--- → ?
Updated•6 years ago
|
Product: Core → Core Graveyard
Updated•6 years ago
|
Product: Core Graveyard → Core
Updated•2 years ago
|
Severity: normal → S3
You need to log in
before you can comment on or make changes to this bug.
Description
•