Stacker News Bug Report
Description:
Based on my testing, it appears that users can upload images using the
File Upload
feature during comment creation without any limitations or associated costs in sats. This unrestricted functionality could potentially be exploited by malicious attackers to inundate the server's hard disk space with spam image uploads.Reproduction Steps:
- Access the comment creation section.
- Click the
File Upload
feature. - Select a folder with a shit load of images and upload them.
- Spam step 3 or have a script to do it for you.
Actual Result:
The current system allows users to upload images without any restrictions.
Expected Result:
Users should be limited in their ability to spam file upload. An easy solution could be having to pay a small fee for each upload.
Impact:
This vulnerability (i guess?) poses a risk of server resource due to potential abuse by malicious actors.