We use cookies to improve your experience. No personal information is gathered and we don't serve ads. Cookies Policy.

ExpressionEngine Logo ExpressionEngine
Features Pricing Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University
Log In or Sign Up
Log In Sign Up
ExpressionEngine Logo
Features Pro new Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University Blog
  • Home
  • Forums

Possible Security Vulnerability?

How Do I?

avori's avatar
avori
67 posts
one month ago
avori's avatar avori

Hello All,

Recently found an email in my inbox from a gentleman named “Sahil”, saying he found a vulnerability with a website. I logged into the admin panel and found that a bunch of small few kb images have been added to the uploads.

I do have 2 front-end facing forms, one for candidates to apply for open positions, and a contact form. Both have a file upload. However no forms have been submitted with these images. I’m assuming someone, perhaps our guy “Sahil” was sending POST requests directly bypassing the form?

Anyway, how would I go about preventing this in the future?

Thanks, Viktor.

       
avori's avatar
avori
67 posts
one month ago
avori's avatar avori

Hmm, my forms do use CSRF tokens.

       
Tom Jaeger's avatar
Tom Jaeger
449 posts
one month ago
Tom Jaeger's avatar Tom Jaeger

Thanks for posting this… What version of ExpressionEngine are you using?

Thanks,

-Tom Jaeger

       
avori's avatar
avori
67 posts
one month ago
avori's avatar avori

Hi Tom, I am using version 7.5.16.

       

Reply

Sign In To Reply

ExpressionEngine Home Features Pro Contact Version Support
Learn Docs University Forums
Resources Support Add-Ons Partners Blog
Privacy Terms Trademark Use License

Packet Tide owns and develops ExpressionEngine. © Packet Tide, All Rights Reserved.