Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Image (security) issues (bludit 3.15) #1544

Open
tezalsec opened this issue Oct 19, 2023 · 1 comment
Open

Image (security) issues (bludit 3.15) #1544

tezalsec opened this issue Oct 19, 2023 · 1 comment

Comments

@tezalsec
Copy link

Hi, I'm new to Bludit and exploring it. I found these two issues concerning the profile issues, I am not sure I should post this here or in the forum or both:

  • when uploading a profile picture of 100 kb, it is uploaded with an endresult of 627 kb! How is this possible? Can I disable any kind of image handling so it just stays the same kb?

  • the profile picture uses the username as filename, this seems like an obvious security issue, allowing people to know the username.

Bludit version : 3.15
PHP 8.1

Thank you.

@tezalsec tezalsec changed the title Image issues (bludit 3.15) Image (security) issues (bludit 3.15) Oct 19, 2023
@Mates-K1
Copy link

Mates-K1 commented Mar 5, 2024

I can confirm both "characteristics".

Bludit version : 3.15
PHP 8.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants