signup-flow

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered an IDOR vulnerability in a WebSocket-based signup flow that allowed account takeover by manipulating UUID parameters during user registration, enabling email changes on arbitrary accounts without authentication.

Mohsin Khan example.com Burp Suite JWT WebSocket
mokhansec.medium.com · kh4sh3i/bug-bounty-writeups · 17 hours ago · details