Skip to content

Latest commit

 

History

History
13 lines (7 loc) · 493 Bytes

vulnerable-code-4.md

File metadata and controls

13 lines (7 loc) · 493 Bytes

SecurityExplained S-16: Vulnerable Code Snippet - 4

Vulnerable Code:

Vulnerable Code

Solution:

The issue in this code snippet is the use of Blacklist (Denylist) instead of using a Whitelist (Allowlist). An attacker can bypass this protection in multiple ways and upload a malicious file on the server.

Code Credits: SonarSource

Follow Twitter Thread