Skip to content
This repository was archived by the owner on Sep 18, 2024. It is now read-only.
This repository was archived by the owner on Sep 18, 2024. It is now read-only.

网页端不需要登录就可上传图片 #46

@GJCav

Description

@GJCav

网页端进入后不登录,直接进入物品编辑界面,上传图片。

虽然点击提交会显示未登录,但是图片确确实实是上传到服务器上了,是个安全漏洞。
(我反手给你传20个2G的图片)

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingweb这是web端的锅

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions