Unrestricted File Upload on https://app.lemlist.com
Medium
L
lemlist
Submitted None
Actions:
Reported by
ctulhu
Vulnerability Details
Technical details and impact analysis
## Summary:
Hi! i found an Unrestricted File Upload on https://app.lemlist.com which let me upload anything.
File Extensions Such as .html and others should not be executed on the server side.
## Steps To Reproduce:
[add details for how we can reproduce the issue]
* 1.) Login to https://app.lemlist.com
* 2.) Go to Settings > Email Signature > Click the 3 Dots > Upload File
{F617850}
* 3.) Download {F617851} and Upload it
* 4.) Right Click and Get the Link of the Uploaded File, Visit the Link.
{F617852}
## Impact
attacker can bypass upload restrictions and deface the page.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Unrestricted Upload of File with Dangerous Type