horizontal-privilege-escalation

2 articles
sort: new top best
clear filter
0 7/10

A critical authentication bypass vulnerability in Companies House allowed unauthenticated access to any company's dashboard by using the browser back button after failing authentication. The flaw exposed personal information (home addresses, email, full dates of birth) for 5 million directors and enabled editing of company details and filing of accounts.

Companies House John Hewitt Ghost Mail Dan Neidle Jonathan Philips ClarityDW Ltd
taxpolicy.org.uk · pavel_lishin · 1 hour ago · details · hn
0 6/10

A CORS misconfiguration in Twitter's niche platform allowed attackers to bypass origin validation by leveraging subdomain prefix matching (niche.co.evil.net) to steal private user data including images, emails, and CSRF tokens synced from Facebook, Instagram, and Twitter. The vulnerability was exploited via a simple JavaScript POC that exfiltrated sensitive information when visited by logged-in users.

Twitter Facebook Instagram niche (Twitter product) Rohan Aggarwal HackerOne Burp Suite
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details