Able to remove the admin access of my program

Disclosed: 2016-07-06 12:49:10 By pardeepbattu02 To security
Unknown
Vulnerability Details
Hey Jobert, There is a functional bug in hackerone, using which i am able to make the my program admin free. This shouldn't be happen in the program because atleast one admin be there in program. Request: PUT /sasas/groups/12307 HTTP/1.1 Host: hackerone.com User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:46.0) Gecko/20100101 Firefox/46.0 Accept: application/json, text/javascript, */*; q=0.01 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br Content-Type: application/json X-Requested-With: XMLHttpRequest Referer: https://hackerone.com/sasas/groups/12307/members/edit Content-Length: 157 Cookie: Connection: close {"id":12307,"name":"Admin","team_members_count":2,"permissions":["user_management","program_management"],"immutable":true,"team_member_ids":[{"id":"17940"}]} Thanks & Regards, Pardeep Battu
Actions
View on HackerOne
Report Stats
  • Report ID: 141629
  • State: Closed
  • Substate: resolved
  • Upvotes: 14
Share this report