OAuth Misconfiguration Vulnerability | Bug Bounty Poc | Type 2 | P3
Автор: Ackeron Technologies & Securities
Загружено: 2023-05-20
Просмотров: 904
Hello All,
Vulnerability Name: Oauth Misconfiguration Vulnerability
Severity: P3 (Medium)
Steps to Reproduce :
1). Go to https://www.fresha.com/auth?type=signup and Create a account using abc@gmail.com
2). Now Signup using Google account of abc@gmail.com
3). Change the email address from abc@gmail.com to bac@gmail.com
4). Verify the email change.
5). Now login using the Google account of abc@gmail.com.
Impact:
After the victim has changed the email, still the attacker has access to the account. Oauth should unlink once the user changes the email.
Thanks for watching :)
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: