0x11 - Email Field Payload Injection
0x11 - Email Field Payload Injection
Pentest Tips & Tricks
A01 - Broken Access Control
A01 - Broken Access Control
A02 - Cryptographic Failures
A02 - Cryptographic Failures
A03 - Injection Attacks
A03 - Injection Attacks
A04 – Insecure Design
A04 – Insecure Design
A05 – Security Misconfiguration
A05 – Security Misconfiguration
A06 – Vulnerable Components
A06 – Vulnerable Components
A07 – Identification and Authentication Failures
A07 – Identification and Authentication Failures
Recon & Attack Surface
Recon & Attack Surface
Tooling & Automation
Tooling & Automation
Creative, Strategic, and Mindset
Creative, Strategic, and Mindset
Bug Bounty $$$
Bug Bounty $$$
AI/ML/LLM/MCP
AI/ML/LLM/MCP
Latest Tips & Tricks
Latest Tips & Tricks
Did you know that email address fields can also be vulnerable to:
• Cross-Site Scripting (XSS)
• Template Injection (SSTI)
• Server-Side Request Forgery (SSRF)
• Parameter Pollution
• Header Injection
99% of modern web applications contain an email field along their features
Whether it's within the register, login, contact forms or user details.
However most of the time, this attack path is overlooked due to assumptions that an email address cannot contain certain characters.
Which is not really true according to the RFC.
If you want to know more, I highly recommend the RTFR (Tread the bleeping RFC) talk on YouTube about email injection -> https://www.youtube.com/watch?app=desktop&v=4ZsTKvfP1g0
How to do it
Find an email field in the target app
Personally I recommend your own's profile email especially if it reflected in the UI
Update the value using the
Email Injectionpayloads in the file attachedReview the result after each update
-
Note that running intruder might not be optimal because it might overwrite previous values
Credit to Inti De Ceukelaire and Intigriti for their amazing research