session-timeout-bypass

1 article
Sort: New Top Best
clear filter
0

A developer at Stripe relied on client-side HTML class disabling during account lockout/session timeout, allowing an attacker with a logged-in session to use browser inspect element to remove the disabled class and bypass authentication checks to invite themselves as an administrator. The vulnerability was fixed after responsible disclosure with a $500 bounty.

Stripe Jon
jonbottarini.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details