Loading HuntDB...

Profile bio at rockstar is accepting control characters

Low
R
Rockstar Games
Submitted None

Team Summary

Official summary from Rockstar Games

This report involved the injection of control characters, such as Null Byte `0x00`, into the profile Bio field in order to cause unexpected, harmful behaviors. Our solution was to both block control characters from being saved on the backend when included in user-input, as well as to suppress the output and rendering of previously-submitted control characters.

Reported by exception

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$350.00

Submitted

Weakness

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)