RTLO char allowed in chat

Disclosed: 2017-02-28 19:44:57 By kontez To snapchat
Medium
Vulnerability Details
Hey all, There seems to be no filtering of strange unicode characters such as U+202E which is an Right-To-Left-Override. I can send messages like "Hey check out my new song at example.com/song[rtlo]3pm.exe" and everyone would see the link as "example.com/songexe.mp3". Links that end with .exe are very suspicious but everyone would click on a link that ends with .mp3, filtering those characters would prevent clickjacking. I tested this on the latest version of the Android App. Thanks, Marvin
Actions
View on HackerOne
Report Stats
  • Report ID: 196222
  • State: Closed
  • Substate: resolved
  • Upvotes: 18
Share this report