Lichess: ImageId Format Injection in Image Upload Endpoint
Discription
The image upload endpoint in the Lichess application did not properly validate the 'rel' parameter, allowing an attacker to inject special characters that broke the expected format of the generated ImageId. This could have led to parsing issues in other parts of the application that relied on the standard ImageId…Read More
References
Back to Main