Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

There are arbitrary file uploads where ordinary users upload avatars #13

Closed
superd1ng opened this issue Mar 1, 2023 · 0 comments
Closed

Comments

@superd1ng
Copy link

Affected versions:v3.1.1

The steps to reproduce

Register an ordinary user arbitrarily, and upload the avatar
image
The front-end restricts the file type, and can only upload image-type files
You can modify the suffix of the malicious file to jpg and then modify it back through packet capture
image

repair suggestion

-The backend increases the inspection of file types and uses whitelist filtering

  • Filter with blacklist
@perfree perfree closed this as completed Jun 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants