-
Notifications
You must be signed in to change notification settings - Fork 11
Open
Description
Summary
Services server crashes when msg.url is undefined in feedback handler.
Affected Code
server-services/start-services.js:577
avatar_url: msg.url + 'favicon.ico', // CRASH if msg.url is undefinedVulnerability
If client sends {"cmd":"feedback"} without url field.
Impact
- Services server crash on feedback
- Denial of service
Proof of Concept
{"cmd":"feedback","email":"test@test.com","comments":"test"}Recommended Fix
avatar_url: (msg.url || '') + 'favicon.ico',
embeds: [{ description: \`> from ${msg.email || 'unknown'}\\n\\n${msg.comments || ''}\` }]References
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels