CRLF Injection — xxx$ — How was it possible for me to earn a bounty with the Cloudflare WAF?

Proviesec
InfoSec Write-ups
Published in
5 min readDec 24, 2022

--

I recently discovered a CRLF injection vulnerability on a popular website. In this blog post, I will describe the vulnerability and the attack scenarios that I was able to demonstrate. I will also discuss the potential impacts of CRLF injection vulnerabilities.

What is CRLF?

--

--