insecure storage of information, you can view any file uploaded to the server without authentication and only with a single link