Origami
Origami copied to clipboard
Origami allows user to upload any file as sample image
Node version: 8.3.0
npm version: 5.5.1
Operating system: Debian Jesse
Command line used: bash
Steps to reproduce:
- Go to any origami demo.
- Try uploading text files and python scripts.
BONUS: If you are the admin of an origami demo, you can do the above steps and upload malicious files and can even run JavaScript on the user's browser.
UPDATE: Have written some code to fix this for the time being. Will make a PR in the morning.
@PalashTanejaPro Did you submit a PR for this?