opyrator icon indicating copy to clipboard operation
opyrator copied to clipboard

Issue regarding determine uploaded file types on MIME

Open nevercodecorrect opened this issue 1 year ago • 2 comments

Hi, i played a bit with the project and noticed one potential issue. In this function, the mime type could be manipulated by remote user, hence he could upload any file with a manipulated MIME header. The description of such potential vulnerability is here. One could use magic code to check the uploaded file type rather than rely on the MIME or extension

nevercodecorrect avatar Feb 18 '24 20:02 nevercodecorrect

This issue is stale because it has been open 90 days with no activity. Remove stale label or comment or this will be closed in 14 days

github-actions[bot] avatar May 19 '24 02:05 github-actions[bot]

Hello, is there any update?

nevercodecorrect avatar May 19 '24 14:05 nevercodecorrect