No filteration of null characters in name field
None
W
Weblate
Submitted None
Actions:
Reported by
blake12356
Vulnerability Details
Technical details and impact analysis
Hello,
##Description:
The account settings page, https://demo.weblate.org/accounts/profile/#account, allows a user to set their username as a null character! A user intercepts the request using a proxy and changes the user name field to %00.
##Mitigation:
I recommend you have filtering of null characters on your account settings page.
Thanks!
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Violation of Secure Design Principles