Sim
Well-known member
- Affected version
- 2.3.4
It seems that all video attachments are stored in the
If someone was to extract the video URL from the page and send it to a 3rd party who does not have access to the forum, they would still be able to view the video.
Steps to reproduce:
This is pretty serious if I'm sharing private video content that can be arbitrarily viewed by 3rd parties or embedded in other sites.
Yes, I get that you'd need to know the URL of the video and if you can access that, then it's fairly trivial for a technically competent person to download the video or the image/document and share it - but it's still unexpected behaviour and sharing a link is quite different to downloading the content and then sharing the content itself.
Either way - why do we go to the trouble of protecting the images and documents if we aren't also protecting videos?
data
directory rather than in internal_data
- which means that they are publicly accessible, even on a private forum, unlike photos or other attachments.If someone was to extract the video URL from the page and send it to a 3rd party who does not have access to the forum, they would still be able to view the video.
Steps to reproduce:
- in a forum that does not have public access, create a post with the following items attached:
- an image
- a document, such as a PDF file
- a video
- copy the URLs for each of the three attached items above
- in a browser that is not logged in to the site, try to access the three URLs
- You should see the following results:
- the image cannot be viewed - you get an error message, as expected
- the document cannot be viewed - you get an error message, as expected
- the video can be viewed without any challenge to log in. This is unexpected behaviour.
This is pretty serious if I'm sharing private video content that can be arbitrarily viewed by 3rd parties or embedded in other sites.
Yes, I get that you'd need to know the URL of the video and if you can access that, then it's fairly trivial for a technically competent person to download the video or the image/document and share it - but it's still unexpected behaviour and sharing a link is quite different to downloading the content and then sharing the content itself.
Either way - why do we go to the trouble of protecting the images and documents if we aren't also protecting videos?
Last edited: