Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

"Create an Account" Major issues #840

Open
hutchibw opened this issue Mar 10, 2017 · 0 comments
Open

"Create an Account" Major issues #840

hutchibw opened this issue Mar 10, 2017 · 0 comments

Comments

@hutchibw
Copy link

hutchibw commented Mar 10, 2017

In the Ayamel production site, the "Create an Account" form accepts almost anything as input.
For example, I can put it a single character into the username form, and as long as it isn't a username that is already taken, thus an account can be created account without inputting any of the other information.

screen shot 2017-03-10 at 1 44 08 pm

Similar issues are occurring on the beta site as long as matching passwords are typed in. For example I was able to create a user named ' OR SELECT * WHERE '1' = '1 (this didn't return any info from the database... but still...)

Anyways, since we are going to get rid of this functionality for Y-Video/future updates, it might be a good idea to get rid of it ASAP just in case.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant