No filteration of null characters in name field

Disclosed: 2017-07-27 11:51:03 By blake12356 To weblate
None
Vulnerability Details
Hello, ##Description: The account settings page, https://demo.weblate.org/accounts/profile/#account, allows a user to set their username as a null character! A user intercepts the request using a proxy and changes the user name field to %00. ##Mitigation: I recommend you have filtering of null characters on your account settings page. Thanks!
Actions
View on HackerOne
Report Stats
  • Report ID: 242945
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report