NastuzziSamy / files_external_gdrive

[BETA - UNSTABLE] GDrive external storage for NextCloud
GNU Affero General Public License v3.0
78 stars 24 forks source link

grant access button has mime sniffing .js file type spoofing vuln #56

Open diveyez opened 4 years ago

diveyez commented 4 years ago

Can you please contact me ASAP outside of Github? Discord: Diveyez#1878

I think one of the people who forked behind you might be actively enhancing that vulnerability to exploit google cloud auth's