Lack of length validation on user address attribute

Disclosed: 2019-04-11 08:32:44 By rohitdua To security
None
Vulnerability Details
Hi The input fields for adding mailing address for swag delivery in ```https://hackerone.com/settings/swags``` are not restricted in input lengths. I was able to add *(and read the contents via my own address page and the team page(who awards the swag))* over **585728 characters** in each of the input fields ```Name, Street, City, State/Province, Postal code, Country, Phone number``` without any restriction or error message. {F113760} This may lead to server side Denial Of Service attack or over memory consumption. You need to decrease input lengths( or add one if missing) Thanks Rohit Dua https://github.com/rohit-dua https://in.linkedin.com/in/rohitdua
Actions
View on HackerOne
Report Stats
  • Report ID: 161947
  • State: Closed
  • Substate: resolved
  • Upvotes: 17
Share this report