Join
[MEDIUM] · Other · Resolved

Business Logic Erorr How I Silently Broke Every Note in a Project Management Platform

BATOT BATOT ████████ 18 Aug 2026

Summary

A business logic flaw in the project management application allows a Project Manager to store arbitrary HTML markup in a project's name without proper server-side validation or sanitization.

By placing a specially crafted HTML payload in the Project Name field, the project can enter a corrupted state where the malicious value is no longer visibly displayed. However, the value remains stored and later interferes with the application's note-creation workflow.

As a result, any user who attempts to create a note on the affected project—including an Administrator—receives a server-side error and cannot create the note.

This makes the issue particularly impactful because a lower-privileged Project Manager can silently corrupt a project and cause a functionality denial that persists across users and sessions.