password-change

2 articles
sort: new top best
clear filter
0 5/10

Researcher discovered full account takeover vulnerability by chaining a missing CSRF token validation on the password change endpoint with a hidden 'uid' parameter discovered via Param Miner, allowing password changes for any user without authentication, resulting in a $1000 bounty.

Mohsin Khan Param Miner Burp Suite James Kettle
mokhansec.medium.com · kh4sh3i/bug-bounty-writeups · 18 hours ago · details
0 7/10

A researcher discovered a P1 account takeover vulnerability by bypassing CSRF protections on a password change endpoint through server-side validation bypass—using a random email address format instead of the victim's actual email allowed successful password changes without requiring the victim's email in the CSRF payload.

Lady Secspeare Bugcrowd
ladysecspeare.wordpress.com · devanshbatham/Awesome-Bugbounty-Writeups · 18 hours ago · details