Loading HuntDB...

Control Character Injection In Messages

Low
R
Rockstar Games
Submitted None

Team Summary

Official summary from Rockstar Games

This report involved the injection of control characters, such as Null Byte `0x00`, into vulnerable fields in the Message endpoints in order to cause unexpected, harmful behaviors. Our solution was to both block control characters from being saved on the backend when included in user-input, as well as to suppress the output and rendering of previously-submitted control characters.

Reported by exception

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$350.00

Submitted

Weakness

Improper Authentication - Generic