TsimpDim/3RStore

Invalid Tag input data crashes the app and causes Denial of Service

Closed this issue · 0 comments

Reproduction Steps

  1. Navigate to https://threerstore.herokuapp.com/login and authenticate with your account credentials
  2. Then, under https://threerstore.herokuapp.com/resources create a new resource
  3. On the resource's tag, enter the following payload, test"><img src=x>
  4. Create the resource and notice that the application has crashed.

Note

As the application has currently crashed, this issue will be updated with more details once it's back up and running.