Skip to main content

Posts

Showing posts with the label microsoft bot exploit

Microsoft Bot Framework - Unvalidated File Upload | Online Service Acknowledgements | Rishu Ranjan

Microsoft Bot Unvalidated File Upload: The security issue allows a malicious actor to upload any file without validating the extension or content type of the file.

Acknowledgment: Microsoft Online Service Acknowledgements for July 2019 (https://portal.msrc.microsoft.com/en-us/security-guidance/researcher-acknowledgments-online-services?rtc=1)