Apr 30th 2022


When a user created with a profile picture and deleted after some time the profile picture of that user is still remain on the server even after deleting the user's account

Proof of Concept

  1. Create a new student with a profile picture
  2. Delete this user
  3. And visit this url{userID of Deleted user}.jpg

Remediation:- Delete the user's profile image rather than unlinking it


Even after deleting the user's profile image remain on server which impact on user's privacy.

2 years ago


Hello @jo125ker

Thank you for your report. Please note photos file name now has a random string so it cannot be predicted and accessed publicly.

François Jacquet marked this as fixed in 9.0 with commit 59d8d0 2 years ago
