Loading HuntDB...

Unrestricted File Upload on https://app.lemlist.com

Medium
L
lemlist
Submitted None
Reported by ctulhu

Vulnerability Details

Technical details and impact analysis

Unrestricted Upload of File with Dangerous Type
## Summary: Hi! i found an Unrestricted File Upload on https://app.lemlist.com which let me upload anything. File Extensions Such as .html and others should not be executed on the server side. ## Steps To Reproduce: [add details for how we can reproduce the issue] * 1.) Login to https://app.lemlist.com * 2.) Go to Settings > Email Signature > Click the 3 Dots > Upload File {F617850} * 3.) Download {F617851} and Upload it * 4.) Right Click and Get the Link of the Uploaded File, Visit the Link. {F617852} ## Impact attacker can bypass upload restrictions and deface the page.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Unrestricted Upload of File with Dangerous Type