Hyper Link Injection while signup
Low
U
UPchieve
Submitted None
Actions:
Reported by
011alsanosi
Vulnerability Details
Technical details and impact analysis
## Summary:
Attacker can add their name to a URL in order to send email containing malicious hyperlinks. while signup
## Steps To Reproduce:
1-Go to https://app.upchieve.org and create account with the first name ```http://attacker.com/ ``` and last name .
2-Now check your email and you notice there is malicious hyperlinks.
█████████
## Supporting Material/References:
█████
## Recommendations for Fixing/Mitigation
Validate users input
## Impact
This permits users to send malicious/phishing links to potential clients. It could also have an effect on how spam filters treat ```app.upchieve.org``` emails.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Input Validation