Send in your ideas. Deadline June 1, 2026
Grant
Theme fund: FileSender
Period: 2022-10 — 2022-10

FileSender IDOR and Rate Limiting

Security improvements to FileSender

FileSender is an open source web application for sending files of any size, quickly and securely. The sender has full control over who receives and can access the files and for which period of time – as it should be. This project is to address a number of issues discovered during a security audit. These issues include possible insecure direct object references during a guest file upload, missing rate limiting for some email notifications which could allow abuse, a modification to a cookie for better security against internal attacks, and dependency updates.