Summary
Any authorized user can use the transaction endpoint to modify any users file, including delete them.
PoC
Use the /api/user/files/transaction endpoint to modify any user's file.
Impact
This does require having the File ID of the file to edit which should greatly reduces impact as I don't think these are exposed.
Summary
Any authorized user can use the transaction endpoint to modify any users file, including delete them.
PoC
Use the
/api/user/files/transactionendpoint to modify any user's file.Impact
This does require having the File ID of the file to edit which should greatly reduces impact as I don't think these are exposed.