Business Logic Error - letting the Name Field blank in froxlor/froxlor
Reported on
Jul 13th 2023
Hello,
I was able to bypass the restriction for setting an admin username and letting the username via spaces blank.
Let's have a look.
As you can see the name is with a red star and therefore required to be filled.
Now we will add2 spaces and let the username blank and save.
As you can see all the names have been left blank.
Thank you for your time.
Impact
Hello,
I was able to bypass the restriction for setting an admin username and letting the username via spaces blank.
Let's have a look.
As you can see the name is with a red star and therefore required to be filled.
Now we will add2 spaces and let the username blank and save.
As you can see all the names have been left blank.
Thank you for your time.
Should also be an issue on current stable 2.x
Hello can you please assign it a CVE.
Thank you very much.
Hello can you please assign it a CVE.
Thank you very much.