Feed on
Posts

Upload of svg images forbidden because of security concerns?

Let’s see whether .svg is supported:

customer-service-bubbles.svg

Yeah, that rocks!

(Might be you will have to scroll down)

Let’s see whether .svg can be uploaded to Media:

Damned, that does not work:

G9gHjl3.png
Horizontal2.webp

My conclusion

AFAIK .svg was not supported in FP 1.3, and so in was ok that Uploader refused to accept images.svg
But FP 1.5.1 DOES support images.svg, so I think those “security concerns” are a bug.

Additional information / research

  • Might be related to Possible XSS via SVG upload –FP #172?
  • An other solution for security issues will be required

Code of my tests above:

[h2]Let’s see whether .svg is supported:[/h2]
[img=https://www.clker.com/cliparts/C/w/9/Q/V/1/customer-service-bubbles.svg] 
[h3]Yeah, that rocks![/h3]
(Might be you will have to scroll down)
[h2]Let’s see whether .svg can be uploaded to Media supported:[/h2] 
[h3]Damned, that does not work:[/h3]  
[img=https://imgur.com/G9gHjl3.png]