Hyper Link Injection while signup

Disclosed: 2022-06-15 10:04:14 By 011alsanosi To upchieve
Low
Vulnerability Details
## Summary: Attacker can add their name to a URL in order to send email containing malicious hyperlinks. while signup ## Steps To Reproduce: 1-Go to https://app.upchieve.org and create account with the first name ```http://attacker.com/ ``` and last name . 2-Now check your email and you notice there is malicious hyperlinks. █████████ ## Supporting Material/References: █████ ## Recommendations for Fixing/Mitigation Validate users input ## Impact This permits users to send malicious/phishing links to potential clients. It could also have an effect on how spam filters treat ```app.upchieve.org``` emails.
Actions
View on HackerOne
Report Stats
  • Report ID: 1166073
  • State: Closed
  • Substate: resolved
  • Upvotes: 15
Share this report