Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r3jx-6xf2-cch5

Опубликовано: 20 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate counterpart when the username is displayed in the UI, potentially leading to confusion.

HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate counterpart when the username is displayed in the UI, potentially leading to confusion.

EPSS

Процентиль: 1%
0.00009
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-156

Связанные уязвимости

CVSS3: 5.4
nvd
3 месяца назад

HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate counterpart when the username is displayed in the UI, potentially leading to confusion.

EPSS

Процентиль: 1%
0.00009
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-156