We use cookies to improve your experience. No personal information is gathered and we don't serve ads. Cookies Policy.

ExpressionEngine Logo ExpressionEngine
Features Pricing Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University
Log In or Sign Up
Log In Sign Up
ExpressionEngine Logo
Features Pro new Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University Blog
  • Home
  • Forums

Possible Security Vulnerability?

How Do I?

avori's avatar
avori
67 posts
2 months ago
avori's avatar avori

Hello All,

Recently found an email in my inbox from a gentleman named “Sahil”, saying he found a vulnerability with a website. I logged into the admin panel and found that a bunch of small few kb images have been added to the uploads.

I do have 2 front-end facing forms, one for candidates to apply for open positions, and a contact form. Both have a file upload. However no forms have been submitted with these images. I’m assuming someone, perhaps our guy “Sahil” was sending POST requests directly bypassing the form?

Anyway, how would I go about preventing this in the future?

Thanks, Viktor.

       
avori's avatar
avori
67 posts
2 months ago
avori's avatar avori

Hmm, my forms do use CSRF tokens.

       
Tom Jaeger's avatar
Tom Jaeger
451 posts
2 months ago
Tom Jaeger's avatar Tom Jaeger

Thanks for posting this… What version of ExpressionEngine are you using?

Thanks,

-Tom Jaeger

       
avori's avatar
avori
67 posts
2 months ago
avori's avatar avori

Hi Tom, I am using version 7.5.16.

       

Reply

Sign In To Reply

ExpressionEngine Home Features Pro Contact Version Support
Learn Docs University Forums
Resources Support Add-Ons Partners Blog
Privacy Terms Trademark Use License

Packet Tide owns and develops ExpressionEngine. © Packet Tide, All Rights Reserved.