Actions
Bug #34
closedAPI Accepts Excessively Large Input Values Without Validation (Potential Resource Abuse)
Status:
Closed
Priority:
Normal
Assignee:
-
Description
Description:
The /api/organizations/add endpoint accepts excessively large input values across multiple fields (e.g., address, city, name) without enforcing any size limits. This allows submission of very large payloads, which can impact performance and data integrity.
Steps to Reproduce:
- Send request to: POST
/api/organizations/add - Provide excessively large input (e.g., 1000–10,000+ characters) in fields such as:
- address
- city
- name
- Submit the request
Expected Result:
API should:
- Enforce maximum input length constraints
- Reject excessively large payloads
- Return validation error (e.g., 400 Bad Request)
Actual Result:
API accepts very large input values
Request succeeds without validation
Large data is stored/processed
NOTE A request in Postman for reproduction of the issue.
Files
Actions