A Security Analysis of Website-Enabled Direct File Uploads to Cloud Storage Services
D. Srihitha Rao D. Praneeth Reddy D. Arun Kumar
Student, Computer Science and Student, Computer Science and Student, Computer Science and
Engineering Engineering Engineering
Guru Nanak Institutions Technical Guru Nanak Institutions Technical Guru Nanak Institutions Technical
Campus (Atunomous) Campus (Atunomous) Campus (Atunomous)
Hyderabad,Telangana,India-501506 Hyderabad,Telangana,India-501506 Hyderabad,Telangana,India-501506
srihithadondula@gmail.com praneethreddydonthireddy@gmail.com arunreddy050204@gmail.com
Dr. Geeta Tripathi
Professor, Computer Science and
Engineering
Guru Nanak Institutions Technical
Campus (Atunomous)
Hyderabad,Telangana,India-501506
hodcse1.gnitc@gniindia.org
ABSTRACT
With the increasing reliance on cloud storage services for handling large volumes of user data, websites have begun enabling direct file uploads from users to cloud platforms. While this approach offers greater convenience and scalability, it also introduces new security challenges due to the involvement of multiple entities, including web users, web servers, and cloud storage providers. In this study, we present the first comprehensive security evaluation of this direct upload model. Through an in-depth investigation, we identify six distinct categories of vulnerabilities and perform large-scale testing across the top 500 websites ranked by Alexa. Our findings reveal that 182 websites (36.4%) utilize cloud storage services, and a focused analysis of 28 popular websites with upload functionality shows that all exhibit at least one of the identified vulnerabilities. In total, we uncover 79 previously unreported vulnerabilities, which we responsibly disclosed to the respective platforms, including major services like Google, Reddit, and CSDN. The positive responses highlight the practical impact of our findings. We further examine the root causes of these issues and suggest effective mitigation strategies. This work contributes valuable insights into the security implications of cloud-based file uploads and aims to guide both developers and researchers in building more secure web applications.