Lichess: ImageId Format Injection in Image Upload Endpoint
Discription

image
The image upload endpoint in the Lichess application did not properly validate the 'rel' parameter, allowing an attacker to inject special characters that broke the expected format of the generated ImageId. This could have led to parsing issues in other parts of the application that relied on the standard ImageId…Read More

Back to Main

Subscribe for the latest news: