This message was deleted.
# questions
b
This message was deleted.
b
Here is the rest of the message : PoC : file uploaded from this account: (url of the stacker base) The XSS payload allowing the execution of a JS alert (for the example): https://cdn.filestackcontent.com/cQBvrlRhShm47ehGjIBr I don't have the agreement to take the hand on the server which hosts this image, know that it is possible for me (via this same file upload module) to ByPass the MIME controls (or file format) in order to upload a document in PHP and thus take the hand on the server itself. Given the severity of the exploits, it is preferable that you look into it before the audit can continue because as it stands the application cannot integrate our application park.
e
Hey @bored-monkey-62761, our dev/security team will be taking a look at it. If we confirm an exploit and deem it a threat, we will definitely be fixing it.
b
Thank you, I got more details from the IT team I will share it to you by pm.
r
A response to this would be generally interesting, if team can share 🙂
👍 2
e
We will share as soon as we have concluded our investigation. 🙂