Temporary attachments should only be viewable by the session/user which adds them

XenForo implements temporary attachments without additional constraints to view them, with the guest posting feature this sadly can be trivially exploited for spam:

BassMan said:
Or this one...

Upload images in the quick editor and never post a reply. Use the URL of those images in an email for various phishing attacks. The URL points to your forum (images are uploaded to your server).
Click to expand...
BassMan said:
I received a message about this with the URLs of the images via the contact form. And then the...
Click to expand...

Read more

Читать далее...
 
Активность
Пока что здесь никого нет
Назад
Верх Низ