10000 [Security 🐛] Trying a non-existing download link exposes filename of last downloaded file · Issue #75 · epoupon/fileshelter · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
[Security 🐛] Trying a non-existing download link exposes filename of last downloaded file #75
Closed
@laurens94

Description

@laurens94

Hi! First of all thanks for fileshelter, I love the simplicity of it and the Docker image makes setting it up amazingly easy!
I just tried it out and it works really well. 👍 I do believe I just found a small bug though:

Whenever I try to download something that doesn't exist, the server downloads a Zero-bytes file with the same filename as the last downloaded file.

For example a URL like this would work: https://fileshelter-demo.poupon.dev/share?id=asdguhahsdugasdg

No contents are exposes, only the filename. This might be of a private file that's password protected.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0