This repository was archived by the owner on Mar 13, 2025. It is now read-only.
This repository was archived by the owner on Mar 13, 2025. It is now read-only.
[$30] able to upload all types of files after changing the extension to ".xlsx" in upload profile data tab #269
Closed
Description
Steps to Reproduce
- Open https://skill-search.topcoder-dev.com/ web app
- Login with tonyj /appirio123
- Select topcoder as organization
- Navigate to third tab
- Now on your system, take a image file and change its's extension to ".xlsx"
- Now click on browse and select the file whose extension is changes in previous step and upload
- Notice the result
Screenshots or Screen Capture
Current Results
able to upload all types of files after changing the extension to ".xlsx" in upload profile data tab
Expected Results
application must validate the MIME type of the file uploaded before saving it. This can be a big security risk.
Browser version and OS version
- Device: MacBook Pro 13 inch
- Browser: Chrome Version 83.0.4103.116 (Official Build) (64-bit)
- OS Version: macOS Catalina 10.15.4