RaSan147 / VoiceAI-Asuna

If you're familiar with the anime Sword art online, you know it! This project is a virtual Assistant for multiple OS
https://ai-asuna.onrender.com
Apache License 2.0
27 stars 5 forks source link

[Bug] blank signup/login form are being accepted #17

Closed RaSan147 closed 1 year ago

RaSan147 commented 1 year ago

Check both js and py

RaSan147 commented 1 year ago

fixed in js

s-b-repo commented 1 year ago

yeah but does not matter if it is accepted what matter is if a you can inject code

RaSan147 commented 1 year ago

yeah but does not matter if it is accepted what matter is if a you can inject code

I don't understand what you've ment, but I'm using python in backend and not even touching the username (oh shit thats a issue) but i don't think code injection will work on me (not using sql or any traditional database)

RaSan147 commented 1 year ago

Oh got it, yeah making (right now) server side changes to slap on the injected code

Thanks (really need a guy like you)

s-b-repo commented 1 year ago

no mean someone can fuzz input and find a way to inject code

RaSan147 commented 1 year ago

Try me 😄 (if you know what to do). Lets see the server burn

RaSan147 commented 1 year ago

Just don't databomb it (I don't have unlimited storage lol)

s-b-repo commented 1 year ago

Try me smile (if you know what to do). Lets see the server burn

that would delete everything so no or have alot of unwanted affects

RaSan147 commented 1 year ago

Lers Try that on you vm (the one you let me use) Making changes tonight