RSS Feed/News Image proxy can be abused too easily

Status
Not open for further replies.

ENXF NET

Administrator
Staff member
Administrator
Moderator
+Lifetime VIP+
S.V.I.P.S Member
S.V.I.P Member
V.I.P Member
Collaborate
Registered
Joined
Nov 13, 2018
Messages
26,865
Points
823

Reputation:

Steps to reproduce
  1. Configure a proxy secret
  2. Start a new post
  3. Insert an external image
  4. Click preview
  5. Copy the generated image URL
Result
The generated proxy.php URL can now be used externally forever until the secret is changed without the image ever being displayed anywhere publically in XenForo

Suggested Mitigation
Make the hashes automatically expire after a configurable expire time

Continue reading...
 
Status
Not open for further replies.
Top