prevent content spoofing on /~username/emails/verify.html

Disclosed: 2017-07-10 09:59:30 By a5tronaut To gratipay
Unknown
Vulnerability Details
**Steps to Verify:** 1. Login to your Gratipay account. 2. Now navigate to the following url `````` https://gratipay.com/~your_username/emails/verify.html?email=your%20account%20has%20expired.%20You%20must%20renew%20it%20to%20use%20your%20account.%20To%20continue%20you%20have%20to%20send%20your%20login%20credentials%20to%[email protected].%20A%20Gratipay%20executive%20will%20contact%20you%20after%20that.%20Sorry%20for%20this%20intereption,%20we%20know%20this&nonce=x `````` POC screenshot attached. Regards Uttam
Actions
View on HackerOne
Report Stats
  • Report ID: 126010
  • State: Closed
  • Substate: duplicate
  • Upvotes: 1
Share this report