Email or username:

Password:

Forgot your password?
Top-level
Sophie Schmieg

@schrottkatze have you tried changing any elements likely to go into the WHERE clause of the SQL?

Although, if that turns out to allow you to change other people's names, you get the ethical conundrum of disclosure possibly also fixing the other client side validation "feature".

2 comments
schrottkatze ⚡

@sophieschmieg no, i'm happy changing my own name. probing for other vulnerabilities is an exercise to the reader

Go Up