users the Manager proxy role when uploading files - a potential vulnerability on production servers.
Attach a file by drag & drop or click to upload