Loading HuntDB...

Hyper Link Injection while signup

Low
U
UPchieve
Submitted None
Reported by 011alsanosi

Vulnerability Details

Technical details and impact analysis

Improper Input Validation
## Summary: Attacker can add their name to a URL in order to send email containing malicious hyperlinks. while signup ## Steps To Reproduce: 1-Go to https://app.upchieve.org and create account with the first name ```http://attacker.com/ ``` and last name . 2-Now check your email and you notice there is malicious hyperlinks. █████████ ## Supporting Material/References: █████ ## Recommendations for Fixing/Mitigation Validate users input ## Impact This permits users to send malicious/phishing links to potential clients. It could also have an effect on how spam filters treat ```app.upchieve.org``` emails.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Input Validation