Link filter protection bypass
Medium
V
Valve
Submitted None
Actions:
Reported by
ramsexy
Vulnerability Details
Technical details and impact analysis
## Description
Hi, there is a protection bypass in the linkfilter function. By using the character 。 (%E3%80%82 url encoded) instead of a normal dot in urls, it is possible to bypass the blocking.
## PoC
Normal request : https://steamcommunity.com/linkfilter/?url=pornhub.com
{F240919}
Bypass : https://steamcommunity.com/linkfilter/?url=pornhub%E3%80%82com
{F240920}
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Open Redirect