@Sonar_Research Which could potentially allow the attacker to execute abritrary commands on the server.
To fix it, you should sanitize the user-provided 'avatar' .
@Sonar_Research This could allow an attacker to inject malicious content into the constructed url. For example, if an attacker provides the string `"; exec("rm -rf /")` as the avatar parameter, the resulting url would be `https://unstable-avatar-service.tdl"; exec("rm -rf /")`,
#Raffle
Don't miss this chance! ๐
Our #HSC22 partners have also brought great gifts for you this time!
Now you just have to earn them ;)
https://t.co/w5RDyALOcb
@Sonar_Research Yes. The code appears to be trying to parse a public or private key from a $_POST variable called cert. However, there is no input validation or sanitization on the $_POST['cert'] variable, so it could potentially contain malicious input.
Especially in the age of social media itโs so easy to wallow in self pity, jealousy and negativity. Itโs always there if you wanna just go look at it and read it. That shit is poison.
Doesnโt mean we bury our head but monitor what and how much you consume. It becomes you.
Not always the case but in my 33 years:
- find the stuff that brings you joy and pursue it. Guard it and earn it. Itโs fleeting and finite but worth the endeavor if true.
- things that bring pain and anger are pursuing you or are at least always nearby. Avoid em.