BeeStation / BeeStation-Hornet

99.95% station. 0.05% bees
https://beestation13.com
GNU Affero General Public License v3.0
200 stars 669 forks source link

Minor href exploit #9281

Open PowerfulBacon opened 1 year ago

PowerfulBacon commented 1 year ago

Noticed in #9271, there is a minor href exploit with med huds as the world time is being accepted as user input which can be anything. This lets you view the stats of anyone at any time if you abuse the exploit.

EvilDragonfiend commented 1 year ago

I am surprised you noticed that now. This is also applied to AI tracking. AI character name tracking especially needs this.

PowerfulBacon commented 1 year ago

But AI tracking doesn't use hrefs to determine time. image AI tracking is sanitised properly.

image The problem with medhuds is that the time is stored inside the href.