British firm asked to change name as it could be used to hack websites
The UK business registrar Companies House has forced a software consultant to change its name after discovering it could lead to cross-site scripting attacks.
The British software engineer had kept his company’s name ““> LTD”. The name could have led to vulnerable websites to execute a script from the site XSS Hunter, which allows devs to discover cross-site scripting errors. It would have affected websites that don’t handle the HTML Code properly and could have mistaken them as blank in the company name section.
“A company was registered using characters that could have presented a security risk to a small number of our customers, if published on unprotected external websites.