Skip to content
This repository was archived by the owner on Mar 13, 2025. It is now read-only.
This repository was archived by the owner on Mar 13, 2025. It is now read-only.

[$30] able to upload all types of files after changing the extension to ".xlsx" in upload profile data tab #269

Closed
@rprakash20

Description

@rprakash20

Steps to Reproduce

  1. Open https://skill-search.topcoder-dev.com/ web app
  2. Login with tonyj /appirio123
  3. Select topcoder as organization
  4. Navigate to third tab
  5. Now on your system, take a image file and change its's extension to ".xlsx"
  6. Now click on browse and select the file whose extension is changes in previous step and upload
  7. Notice the result

Screenshots or Screen Capture

Screenshot 2020-07-12 at 8 45 57 PM

Screenshot 2020-07-12 at 8 46 08 PM

Current Results

able to upload all types of files after changing the extension to ".xlsx" in upload profile data tab

Expected Results

application must validate the MIME type of the file uploaded before saving it. This can be a big security risk.

Browser version and OS version

  • Device: MacBook Pro 13 inch
  • Browser: Chrome Version 83.0.4103.116 (Official Build) (64-bit)
  • OS Version: macOS Catalina 10.15.4

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions