Loading HuntDB...

RTLO char allowed in chat

Medium
S
Snapchat
Submitted None
Reported by kontez

Vulnerability Details

Technical details and impact analysis

UI Redressing (Clickjacking)
Hey all, There seems to be no filtering of strange unicode characters such as U+202E which is an Right-To-Left-Override. I can send messages like "Hey check out my new song at example.com/song[rtlo]3pm.exe" and everyone would see the link as "example.com/songexe.mp3". Links that end with .exe are very suspicious but everyone would click on a link that ends with .mp3, filtering those characters would prevent clickjacking. I tested this on the latest version of the Android App. Thanks, Marvin

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

UI Redressing (Clickjacking)