This vendor is so terrible.
Its not just this, its everything.
At one point I found their image loader just let me load any file on their server something like <img src="imageloader.asp?path=c:\inetpub\somefolder\some.jpg" /> which was easily replaced with any file on the server in order to stream it.
When I discussed it with their security team they changed it to something like <img src="imageloader.asp?path=HKJSHD*IY#(#:DJGT..." /> but every image still starts with the same prefix leading me to believe that is the representation of c:\ etc in whatever lame homegrown encryption method they tried to use.
Its scary that they are in the cloud business storing sensitive information.
omg love it
I die so cute xoxo. I miss you every single day of my life.