mirror of
https://github.com/gotify/server.git
synced 2026-05-08 14:26:56 +08:00
The application image file upload allowed authenticated users to upload malious .html files. Opening such a file like https://push.gotify.net/image/ViaxrjzNowdgL-xnEfVV-Ggv5.html would allow the attacker to execute client side scripts. The application image upload will now only allow the upload of files with the following extensions: .gif, .png, .jpg and .jpeg.
154 B
13x14px
154 B
13x14px