Access to alerta.khanacademy.org leak sensitive data

Disclosed: 2021-09-08 08:36:43 By myominthu_sec To khanacademy
Critical
Vulnerability Details
Hi , I found to access https://alerta.khanacademy.org/ using signup bypass.That leak access to sensitive data of khanacademy.org Step To Reproduce: 1. Go to https://alerta.khanacademy.org/#/signup 2. Inspect Q and remove ng-hide {F1121291} 3. You got Signup Form. Signup account using [email protected] mail. {F1121292} 4. When you successfully signup,You access alerta.khanacademy.org without confirm email. {F1121297} If you not login direct . 1. Go to alerta.khanacademy.org/#/login. 2. Inspect Q and remove ng-hide {F1121293} 3. Login with your register info. {F1121294} ## Impact Attacker can access alerta dashboard Thanks, @nightmare_msf
Actions
View on HackerOne
Report Stats
  • Report ID: 1061664
  • State: Closed
  • Substate: resolved
  • Upvotes: 26
Share this report