Reading Any File With MissionsAPI

#43 · closed · 1 comments

View on GitHub ↗

warriordeere

It is possible to read any file on the user client (NextJS Server Side) by using the API to read mission files, which is not intended. e.g.: If you run the app in dev mode (`npm run dev`) and then open `http://localhost:3000/api/mission/file?path=../../build.rs` in the browser, the content of the file is displayed even though it is not in the `/data/missions/...` directory. I'm not sure how this is potentially exploitable, but I would rather consider restricting access to the ``data/missions/...`` folder. If necessary, this can be extended to the whole data folder for other APIs, but nothing beyond that.

Comments

warriordeere

✅ Resolved in https://github.com/WarriorDeere/dispond/commit/79da43c4cd9a5742d2421b3113a2de9a56109b43