Master Secure Coding

Level up your security skills with hands-on code review challenges. Identify and fix vulnerabilities to become a better engineer.

Challenge of the DayMedium
150 points

Media Manager

Review the codebase for 'Media Manager' - a custom CMS that allows employees to upload and manage media files for their marketing campaigns. The platform was built using Express.js and AWS S3 for storage. The security team is concerned about the file upload functionality after detecting suspicious files in the S3 bucket during a routine audit. Examine how file uploads are handled to identify potential security issues.

WEBNODE.JSFILE UPLOAD

Vulnerable Code

javascript

Instructions:

  1. Browse through the files to understand the application structure
  2. Find and click on the line containing the XSS vulnerability
  3. Click "Check Line" to verify your answer
ENTERPRISE SOLUTION

Secure Your Engineering Team

Build a security-first culture with our enterprise training platform. Custom challenges, team analytics, and dedicated support for your organization.

Team Dashboard

Track progress and manage users with ease

Custom Challenges

Tailored to your tech stack and industry

SSO Integration

Seamless authentication for your team

Priority Support

Dedicated account manager and SLA

Ready to scale security training?

Join leading companies who trust us to train their engineering teams on secure coding practices.

Contact Sales

Volume-based pricing available