Skip to content

v1.0.5: Resolve CSRF vulnerability

Choose a tag to compare

@Neztore Neztore released this 02 Aug 19:28
· 69 commits to master since this release

This release resolves a CSRF vulnerability present within the server.
This means that if you are logged into a Save-Server instance and you browse to a malicious site they could perform some actions such as creating Redirects, Deleting files, creating or updating users (If root)

They cannot GET files with this vulnerability, so they could not view your gallery - only modify it.