Skip to main content
Nintex Community Menu Bar

Bypassing attachment control

  • March 4, 2025
  • 2 replies
  • 30 views

Shivanipaul
Nintex Employee
Forum|alt.badge.img+1

Hi,

There is an issue flagged by a customer. “Users can upload any file type by bypassing the Attachment Control. This issue has been flagged by our Information Security Team.”

2 replies

Forum|alt.badge.img+15
  • Scholar
  • March 4, 2025

Can you clarify what it means by “bypassing the attachment control”? The control itself does have properties to specify what file types are allowed, I’m assuming there was a way to get around whatever file types were configured there?


Shivanipaul
Nintex Employee
Forum|alt.badge.img+1
  • Author
  • Nintex Employee
  • March 4, 2025

Hi, the user is able to bypass the custom two-factor authentication mechanism by intercepting the request and manipulating the data to redirect to the main page.