We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
One can exploit a XSS to redict the user by uploading a malicious svg on user's avatar
Do not expose the files folder to the web.
Are there any links users can visit to find out more?
If you have any questions or comments about this advisory:
mail us at [email protected]
Impact
One can exploit a XSS to redict the user by uploading a malicious svg on user's avatar
Patches
Workarounds
Do not expose the files folder to the web.
References
Are there any links users can visit to find out more?
For more information
If you have any questions or comments about this advisory:
mail us at [email protected]