EddiesTech / eccomments

Comments using utterances for pages on my website, eddiecoldrick.com
0 stars 0 forks source link

profile-pictures-vulnerability #2

Open utterances-bot opened 3 months ago

utterances-bot commented 3 months ago

Profile Pictures Vulnerability — Eddie Coldrick

Here's a write-up of a security vulnerability that I found and reported to a company regarding profile pictures

https://eddiecoldrick.com/profile-pictures-vulnerability

tiagorangel2011 commented 3 months ago

Pretty interesting post. I agree that normally incremental user ids are not the best idea, normally I like to use random UUIDs to prevent problems like this, they're pretty easy to work with.