Hyper Link Injection while signup
Low
Vulnerability Details
## Summary:
Attacker can add their name to a URL in order to send email containing malicious hyperlinks. while signup
## Steps To Reproduce:
1-Go to https://app.upchieve.org and create account with the first name ```http://attacker.com/ ``` and last name .
2-Now check your email and you notice there is malicious hyperlinks.
█████████
## Supporting Material/References:
█████
## Recommendations for Fixing/Mitigation
Validate users input
## Impact
This permits users to send malicious/phishing links to potential clients. It could also have an effect on how spam filters treat ```app.upchieve.org``` emails.
Actions
View on HackerOneReport Stats
- Report ID: 1166073
- State: Closed
- Substate: resolved
- Upvotes: 15