https://bugzilla.wikimedia.org/show_bug.cgi?id=22933

           Summary: Upload a new version bypasses file extension checks
           Product: MediaWiki
           Version: unspecified
          Platform: All
        OS/Version: All
            Status: NEW
          Severity: major
          Priority: Normal
         Component: Images and files
        AssignedTo: [email protected]
        ReportedBy: [email protected]
                CC: [email protected], [email protected]


When you choose "upload a new version", you can upload an arbitrary file type.
For instance, you can upload a gif and then reupload a BMP file on top of it.

By default this will succeed, because by default the "ignore warnings" option
is checked. This cannot be the intent. The ignore warnings option should
probably not be checked by default.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to