Here is the rest of the message :
PoC :file uploaded from this account:(url of the stacker base)The XSS payload allowing the execution of a JS alert (for the example):https://cdn.filestackcontent.com/cQBvrlRhShm47ehGjIBrI don't have the agreement to take the hand on the server which hosts this image, know that it is possible for me (via this same file upload module) to ByPass the MIME controls (or file format) in order to upload a document in PHP and thus take the hand on the server itself.Given the severity of the exploits, it is preferable that you look into it before the audit can continue because as it stands the application cannot integrate our application park.
e
elegant-eve-85294
01/26/2022, 10:00 AM
Hey @bored-monkey-62761, our dev/security team will be taking a look at it. If we confirm an exploit and deem it a threat, we will definitely be fixing it.
b
bored-monkey-62761
01/26/2022, 12:52 PM
Thank you, I got more details from the IT team I will share it to you by pm.
r
rapid-state-99797
01/26/2022, 6:15 PM
A response to this would be generally interesting, if team can share 🙂
👍 2
e
elegant-eve-85294
01/27/2022, 9:09 AM
We will share as soon as we have concluded our investigation. 🙂