
Eyodav/OpenPLC-Insecure-File-Upload
Releases0
Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without authentication, allowing stored XSS or malicious content delivery .
Collections containing this project
Showing collections based on your access.
This project is not in any collections you can view.