• 0 Posts
  • 3 Comments
Joined 2 years ago
cake
Cake day: June 2nd, 2023

help-circle
  • Cheers for that. Many of these issues allow an authenticated user to do admin actions if they do the right things, so it seems you should never allow a user that you don’t fully trust to have an account.

    But outside of this, there isn’t anything in there that on its own worries me given the nature of the platform (that is, that if it all burnt down I could retrieve all data from other sources). I’m no expert but a cursory look shows a bunch of potential issues that may be layered with other issues but no clear attack path except with prior knowledge.

    These should obviously be fixed but there’s nothing that makes me want to rip my server off the open internet in a hurry.