GitHub - code5ecure/ChatVia: Themesbrand ChatVia Vulnerabilites · GitHub
Skip to content

code5ecure/ChatVia

Folders and files

Repository files navigation

ChatVia

Themesbrand ChatVia Vulnerabilites

Broken Object Level Authorization:

  1. Capture any other user IDs through a user search request. image

  2. Capture image upload request. (below image) image

  3. Replace other user id with your id and send the request. image

Malicious File Upload:

  1. Capture profile image upload request and then chane the type and content to upload html file (containing javascript code). image
  2. Below image is the url of uploaded file. image

About

Themesbrand ChatVia Vulnerabilites

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

Contributors