8.3.34 Set 'Include local directory path when uploading files to a server' to 'Enabled:Disable'

Information



This policy setting controls whether or not local path information is sent when the user is
uploading a file via an HTML form. If the local path information is sent, some information
may be unintentionally revealed to the server. For instance, files sent from the user's
desktop may contain the user name as a part of the path. If you enable this policy setting,
path information is sent when the user is uploading a file via an HTML form. If you disable
this policy setting, path information is removed when the user is uploading a file via an
HTML form. If you do not configure this policy setting, the user can choose whether path
information is sent when he or she is uploading a file via an HTML form. By default, path
information is sent. The recommended state for this setting is- Enabled-Disable.

*Rationale*

A site hosted by a malicious user could use this feature to gather information about the file
system structure of the user's computer.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Include local path
when user is uploading files to a serverThen set the Include local directory path when uploading files to a server
option to Disable.

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CSCv6|3.1

Plugin: Windows

Control ID: f145accfbca454f8d85eed2c017219179a21b4f5fdf343b99396f9222cdecb2f