Unrestricted file upload on the image of contacts

Disclosed: 2020-07-08 15:15:35 By hitman_47 To nextcloud
Low
Vulnerability Details
When uploading an image for a contact, on the file upload pop up window it shows that it can accept all files of any data type. For my testing I uploaded a sample executable, named 'SimpleCrackMe.exe' which doesn't do really do anything without passing parameters to it on a terminal when running it. The file was uploaded successfully. ## Impact An attacker could upload a dangerous executable file like a virus, malware, etc.. If you don't think this is a vulnerability, please let me close the report myself so that I don't lose points
Actions
View on HackerOne
Report Stats
  • Report ID: 808287
  • State: Closed
  • Substate: resolved
  • Upvotes: 17
Share this report