signup-vulnerability

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered an IDOR vulnerability in a WebSocket-based signup flow that allowed account takeover by modifying UUID parameters during user registration, enabling email change on arbitrary accounts without proper authorization checks.

Mohsin Khan example.com
mokhansec.medium.com · kh4sh3i/bug-bounty-writeups · 7 hours ago · details