Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fileboard filenames are not sanitized on server #6

Open
9san opened this issue Mar 20, 2020 · 0 comments
Open

Fileboard filenames are not sanitized on server #6

9san opened this issue Mar 20, 2020 · 0 comments
Labels
bug Something isn't working High Priority PHP PHP related

Comments

@9san
Copy link
Owner

9san commented Mar 20, 2020

XSS potential is there, links can verifiably be broken to not work (just 404s). Have not tried to break the html tags though. Solution should be to do like imageboard, just save unix file and do display/download to show the original filename. Result will be safe, and same for end user. Alternatively sanitize it, but I'm not a huge fan of saving the og filenames on the server either way.

@9san 9san added bug Something isn't working PHP PHP related High Priority labels Mar 20, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working High Priority PHP PHP related
Projects
None yet
Development

No branches or pull requests

1 participant