Unrestricted File Upload on https://app.lemlist.com

Disclosed: 2020-04-01 09:19:42 By ctulhu To lemlist
Medium
Vulnerability Details
## Summary: Hi! i found an Unrestricted File Upload on https://app.lemlist.com which let me upload anything. File Extensions Such as .html and others should not be executed on the server side. ## Steps To Reproduce: [add details for how we can reproduce the issue] * 1.) Login to https://app.lemlist.com * 2.) Go to Settings > Email Signature > Click the 3 Dots > Upload File {F617850} * 3.) Download {F617851} and Upload it * 4.) Right Click and Get the Link of the Uploaded File, Visit the Link. {F617852} ## Impact attacker can bypass upload restrictions and deface the page.
Actions
View on HackerOne
Report Stats
  • Report ID: 722919
  • State: Closed
  • Substate: resolved
  • Upvotes: 13
Share this report