Burp Suite User Forum

Create new post

File upload vulnerability

Mahesh | Last updated: Apr 19, 2021 03:47AM UTC

If the application is taking PDF then is it possible file upload functionality attack?

Hannah, PortSwigger Agent | Last updated: Apr 19, 2021 12:37PM UTC

You may find the following documentation helpful: https://portswigger.net/kb/issues/00500980_file-upload-functionality Additionally, one of our researchers, Gareth, has recently published some research on data exfiltration in PDFs you may find interesting. You can find his whitepaper and talk here: https://portswigger.net/research/portable-data-exfiltration

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.