Loading HuntDB...

No filteration of null characters in name field

None
W
Weblate
Submitted None
Reported by blake12356

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
Hello, ##Description: The account settings page, https://demo.weblate.org/accounts/profile/#account, allows a user to set their username as a null character! A user intercepts the request using a proxy and changes the user name field to %00. ##Mitigation: I recommend you have filtering of null characters on your account settings page. Thanks!

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Violation of Secure Design Principles