PsiTransfer: Violation of the integrity of file distribution
Moderate severity
GitHub Reviewed
Published
Apr 5, 2024
in
psi-4ward/psitransfer
•
Updated Apr 9, 2024
Description
Published to the GitHub Advisory Database
Apr 5, 2024
Reviewed
Apr 5, 2024
Published by the National Vulnerability Database
Apr 9, 2024
Last updated
Apr 9, 2024
Summary
The absence of restrictions on the endpoint, which allows you to create a path for uploading a file in a file distribution, allows an attacker to add arbitrary files to the distribution.
Details
Vulnerable endpoint: POST /files
PoC
Result:
Impact
The vulnerability allows an attacker to influence those users who come to the file distribution after him and slip the victim files with a malicious or phishing signature.
References