Multiple issues with Markdown and URL parsing

Disclosed: 2016-04-21 04:25:48 By pisarenko To security
Unknown
Vulnerability Details
LOOK . 1) html example: `[*<http://myfuneral.ru/>*_<[email protected]>_](https://hackerone.com/pisarenko)` copy + past look rezult: [*<http://myfuneral.ru/>*_<[email protected]>_](https://hackerone.com/pisarenko) mailto:[email protected]" 2) here the situation is more complicated , the fact that I have mail `[email protected] [email protected]` copy past look rezult: [email protected] [email protected] (click one link and two link) 2.1) I don't know correctly or not , but look this (possibly a user visited a malicious link) www.hackerone.com%2Fbugs%3Fsubject=user&report_id=81070&view=all&substates%5B%5D=new&substates%5B%5D=triaged&substates%5B%5D=needs-more-info&substates%5B%5D=resolved&substates%5B%5D=not-applicable&substates%5B%5D=informative&substates%5B%5D=duplicate&substates%5B%5D=spam&[email protected]/&sort_type=latest_activity&sort_direction=descending&limit=25&page=1 (click and Proceed) 3) I attached image , the button is not valid if you insert the profile in the WebSite `http://vk.com/i.luck?hackerone@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@` look go to https://hackerone.com/pisarenko/thanks and click "Go back to profile" (not work) i think has decided that this report is not eligible for a bounty , but you need to fix thanks .
Actions
View on HackerOne
Report Stats
  • Report ID: 113070
  • State: Closed
  • Substate: resolved
  • Upvotes: 6
Share this report