#25 File names can overwrite other resources

Open
opened 5 years ago by sindre · 0 comments
sindre commented 5 years ago

When uploading a file it can overwrite other files, even those ondifferent levels due to lack of input validation. This is differentfrom uploading, as even without checking for file name, itshould be checked that it won’t overwrite another file.

When uploading a file it can overwrite other files, even those ondifferent levels due to lack of input validation. This is differentfrom uploading, as even without checking for file name, itshould be checked that it won’t overwrite another file.
sindre added this to the Required fixes milestone 5 years ago
sindre added the
webpy
label 5 years ago
sindre added the
bug
label 5 years ago
sindre added the
security misconfiguration
label 5 years ago
sindre modified the milestone from Required fixes to Optional vulnerabilities 5 years ago
Sign in to join this conversation.
Loading…
Cancel
Save
There is no content yet.