Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Files of any type can be uploaded as "images" #113

Open
altheaden opened this issue Mar 29, 2024 · 0 comments
Open

Files of any type can be uploaded as "images" #113

altheaden opened this issue Mar 29, 2024 · 0 comments
Labels
backend Back-end development. frontend Front-end development.

Comments

@altheaden
Copy link
Collaborator

This is done by specifying an image file extension in the uploaded file title (e.g., uploading my-script.js as my-script.png). The browser still processes this as the given file extension (e.g., .png), so it's not actually executing any code. However, the file is able to be hosted, which feels like a vulnerability.

@altheaden altheaden added frontend Front-end development. backend Back-end development. labels Mar 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backend Back-end development. frontend Front-end development.
Projects
None yet
Development

No branches or pull requests

1 participant