Hacksplaining
FeaturesLessonsEnterpriseThe BookOWASP Top 10PCI Compliance
Sign Up
Log In
FeaturesLessonsEnterpriseThe BookOWASP Top 10PCI Compliance Sign Up Log In

File Upload Vulnerabilities

Firstly, uploaded files do not get renamed as part of the upload process. The file name appears in the URL of the profile image when it is published.

Firstly, uploaded files do not get renamed as part of the upload process. The file name appears in the URL of the profile image when it is published.

A hacker
example.com/profile/edit
A file chooser dialog
YOUR PROFILE
An anonymous profile
 USERNAME
Mal
Lessons
Glossary
Terms and Conditions
Privacy Policy

© 2026 Hacksplaining Inc. All rights reserved. Questions? Email us at support@hacksplaining.com