
HCheong147352 (Community Member) asked a question.
for our application, this function is to let user to upload their documents (picture and pdf file) so we cannot hard code the file name in logic. May i know there have any suggestion on how to fix this finding?
We had also implement the fix file path and extension checking but get the same finding also.
.png)
Hi @HCheong147352 (Community Member),
I recommend reading through all the possible controls that are described in this article, and choosing the ones most appropriate to your use-case.
Note that in most cases, you would need to enter a mitigation into the Veracode Platform that describes to your Security Team what those controls are.
As you are allowing users to upload files, I would also recommend reading the OWASP File Upload Cheat Sheet.
Kind regards,
Duncan