Full Path Disclosure in password lock

Disclosed: 2017-10-16 05:51:57 By supernatural To paragonie
Unknown
Vulnerability Details
Hi, Password input must be string but not checked in PasswordLock lib, It will throw an exception on `hash` function call Warning: hash() expects parameter 2 to be string So you must validate it in `hashAndEncrypt` and `decryptAndVerify` Regards
Actions
View on HackerOne
Report Stats
  • Report ID: 115422
  • State: Closed
  • Substate: informative
Share this report