file full path discloser.
Unknown
Vulnerability Details
Hi,
Paragonie security team i found one directory browsing vulnerability in php-encryption-master where the user input will not been filtered from any security layer.
let me show you.
there is a autoload.php page in the php-encryption-master. where the input src will b used to browse the directory so this input will not been tested and fetch the file from directory and return to user.
this attack will highly affect your product and may invite for other attack to.
so i hope you will protch it as soon as possible.
thank you,
security researcher,
lucky sen
Actions
View on HackerOneReport Stats
- Report ID: 116057
- State: Closed
- Substate: informative
- Upvotes: 1