Skip to main content
ArcBlock Community

Text/code injection @ https://www.arcblock.io

Abir Khan
Developers
blocklet-serverimpact-highqualifiedresolvedrewardedsecurity

## Summary:

I've found a TEXT/CODE injection Bug on your site https://www.arcblock.io . /.well-known/service/blocklet/og.png?title= parameter is vulnerable to TEXT/CODE injection.

## Steps To Reproduce:

arc injection.png

## Impact

Attacker could execute text at page. As a result an attacker can fool the victim.

Thanks and Best Regards

1 reply

wangshijun22 months ago

Hi, this issue is verified and improved in the latest beta release, however this API supports customized title and description.

Reply