Profile bio at rockstar is accepting control characters
Low
R
Rockstar Games
Submitted None
Team Summary
Official summary from Rockstar Games
This report involved the injection of control characters, such as Null Byte `0x00`, into the profile Bio field in order to cause unexpected, harmful behaviors. Our solution was to both block control characters from being saved on the backend when included in user-input, as well as to suppress the output and rendering of previously-submitted control characters.
Actions:
Reported by
exception
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$350.00
Submitted
Weakness
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)