Skip to content

Vulnerability Found on WebApp #13

Description

@JaymeHebinck

Hi there!

Recently, I came across a vulnerability on the WebApp, where concatenating some capitalised words with underscores ('_') in between leads to some kind of secret code, some may see as a 'point' for some 'assignment'. This seems like a red FLAG{ to me, so I wanted to address this.

Checklist

  • I created at least 5 attack-defence trees using your tool.
  • I read your documentation.
  • I read other ISSUES on this GitHub page.
  • I already found some other vulnerabilities in the past. Seems like your trees ARE vulnerable.

How to Reproduce
To reproduce this vulnerability, please navigate to the most IMPORTANT webpage on the website, the index page. Look around, try some things, and sometimes I come across these weird codes. They seem to be FOR some kind of assignment. When you copy them, they will have the format I just described. They seem to be hidden in places where SECURITY} is weaker on the website. I even found one of them in this very issue.

Verbose Output
Usually, I would provide the raw output of the console. However, in this specific case, this is not relevant. Therefore, I will leave this section empty.

I'm looking forward to seeing your system completely patched and safe!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions