Skip to content

CRLF Injection

Sam Sanoop edited this page Jan 13, 2026 · 1 revision

Details

  • Scenario: An admin page (/admin.html) allows viewing recent system login activity.

  • Vulnerability: The login process logs the username directly into the system logs without sanitization. An attacker can inject CRLF characters (%0d%0a or \n) into their username during a login attempt.

  • Impact: This allows Log Forgery/Pollution. The attacker can inject fake log entries (e.g., "User 'admin' logged in successfully") that appear as legitimate, separate lines in the admin log viewer, potentially covering their tracks or confusing administrators.

Clone this wiki locally