Lack of input validation in e-mail & user name, job title, company name field
Low
Vulnerability Details
Hi,
During sign up input validation didn't deploy properly on e-mail & name field. I've tested inputing following e-mail during sign up:
``hacker~%@gmail.com``
Your system send email to verification the account though the e-mail address is invalid as gmail doesn't allow user to sign up using special characters like ``%,~`` etc.
{F208264}
Another issue is during sign up name field & from account profile edit option name feild, job title, company name field also failed to validate user input and accept special characters like ``$, %, ~,!,{} ``. I've tested this using my account ``[email protected]``
{F208268}
{F208270}
Hope you'll deploy a quick fix. I look forward to hear backck from you, thank you!
Actions
View on HackerOneReport Stats
- Report ID: 254927
- State: Closed
- Substate: informative