MediaCrush / MediaCrush

A website for sharing media
https://mediacru.sh
MIT License
1.34k stars 130 forks source link

Anyone could delete anyone's files #652

Closed SaschaMester closed 9 years ago

SaschaMester commented 9 years ago

Let an uploaded file be available under mediacru.sh/ABCDEF ( fictive link to have an example - file won't exist ).

Anyone who knows this link will be able to delete the file by calling mediacru.sh/api/ABCDEF/delete

This will be pretty interesting for attackers.

ddevault commented 9 years ago

That's not how it works.