perfact::mpa Insecure Direct Object Reference
Posted by deepcore on March 2, 2016 – 8:02 pm
SySS GmbH found out that unauthorized users are able to download arbitrary files of other users that have been uploaded via the file upload functionality. As the file names of uploaded files are incremental integer values, it is possible to enumerate and download all uploaded files without any authorization.
Post a reply
You must be logged in to post a comment.