[Plugin: Simpler CSS] CSS Expressions?
-
One can write CSS expressions that invoke javascript and are interpreted in IE. This could potentially allow an attacker to do all sorts of nasty things through CSS-injected javascript.
Does this plugin deal with css expressions?
A quick overview:
https://mark-story.com/posts/view/css-expressions-in-ie-and-scoping
We’re considering using it on blogs.law.harvard.edu, but I wanted to know if you’d looked into this issue. I didn’t see anything specific in the simpler_css_filter() function and in my testing css expressions got through unscathed.
–DJCP
Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
- The topic ‘[Plugin: Simpler CSS] CSS Expressions?’ is closed to new replies.