RSS Feed/News XenForo accepts long passwords with extra characters appended

Status
Not open for further replies.

ENXF NET

Administrator
Staff member
Administrator
Moderator
+Lifetime VIP+
S.V.I.P.S Member
S.V.I.P Member
V.I.P Member
Collaborate
Registered
Joined
Nov 13, 2018
Messages
31,418
Points
823

Reputation:

Hi,
Today I noticed a strange behavior with long passwords on my XenForo forum.

I created a very long password:

Code:

Code:
https://5d8efaa502c219c3.demo-xenforo.com/2310/index.php
name admin and password 2222nhxb?;Fwgffx*nLLc;ESAH<,r|i3g2]7:DC?)9Rugd_Y;4Q@j`>tp,CDwtt6twSazmd(UQ^:z|I(tiU,2222

Logging in with the exact password works normally. However, if I append extra characters to the end of the password, I can still log in successfully. For example, all of these passwords are accepted...

Read more

Continue reading...
 
Status
Not open for further replies.
Top