Earlier quoted context omitted.
There should be an HTML tag or something that downloads and embeds HTML from a remote site without scripting
https://developer.mozilla.org/en-US/docs/Web/HTML/Element#em... or already exist. maybe they would work?
It was shipped behind a flag with an initial implementation vulnerable to a same origin policy bypass as well as local file disclosure. As far as I can tell the only reason it wasn't assigned a Moz standards position of "harmful" is because Google argued "it's actually still a work in progress!" (three years ago).
Refs:
- https://research.securitum.com/security-analysis-of-portal-e...