AlexDarigan / secureapp

0 stars 0 forks source link

Malicious Files can be invoked by pointing FileToView at external files #2

Closed AlexDarigan closed 2 months ago

AlexDarigan commented 3 months ago

image

Page: Auth2.php

image

Point that query param to an external hosted file can cause trouble.