Unrestricted File Upload on https://auth.ratelimited.me

Disclosed: 2019-05-18 15:27:21 By daniel_v To ratelimited
Unknown
Vulnerability Details
Hello security team, Have found a way to upload files that aren't images on https://auth.ratelimited.me/ Steps to reproduce: 1. Login at https://auth.ratelimited.me/ 2. Click "change photo" and intercept with a tool (used burpsuite) 3. Choose "gravatar" option and change the 'url' parameter to anything you would like 4. Done Ps: The same occurs when you intercept "no photo" option Ps2: I could not execute code through this, but i thought it was a valid report because i tried to upload .txt files in "upload photo" options and it was not allowed. If you need further information, please contact me Best Regards, Daniel ## Impact possibility of uploading anything rather than images
Actions
View on HackerOne
Report Stats
  • Report ID: 463604
  • State: Closed
  • Substate: resolved
  • Upvotes: 21
Share this report