RTLO Injection leads to URi Spoofing

Disclosed by
nt3c's avatar
nt3c
  • Engagement Asana
  • Disclosed date almost 3 years ago
  • Priority P5 Bugcrowd's VRT priority rating
  • Status Informational This vulnerability is seen as an accepted business risk
Summary by nt3c

t was possible to perform RTLO Injection (Right To Left Override Injection). This technique takes advantage of \u202E, a non-printing Unicode character that causes the text that follows it to be displayed in reverse it is commonly used to disguise a string and/or file name and/or url to make it appear benign and to bypass security defences.

Activity
  1. y3t1’s avatar
    y3t1 Customer published the disclosure report

    ()

  2. nt3c’s avatar
    nt3c requested disclosure

    ()

  3. soheesec_bugcrowd’s avatarbugcrowd logo
    soheesec_bugcrowd changed the state to Informational

    ()

  4. soheesec_bugcrowd’s avatarbugcrowd logo
    soheesec_bugcrowd sent a message

    ()

  5. nt3c’s avatar
    nt3c sent a message

    ()Edited

  6. nt3c’s avatar
    nt3c created the submission

    ()