Subdomain Takeover at course.oberlo.com

Disclosed: 2022-12-01 19:22:28 By m7mdharoun To shopify
None
Vulnerability Details
Hi, I was able to takeover your subdomain `course.oberlo.com` via using `kajabi` services. ## `Poc :` visit https://course.oberlo.com/ you will see my poc https://web.archive.org/web/20220904143512/https://course.oberlo.com/ ## `Suggested Fix :` Clear your subdomain DNS. ## Impact Subdomains Takeovers can be use in many things : Malware Phishing / Spear phishing XSS Authentication bypass Open Redirects True access .. etc **************************************** Kind Regards, Mohamed Haron.
Actions
View on HackerOne
Report Stats
  • Report ID: 1690951
  • State: Closed
  • Substate: resolved
  • Upvotes: 11
Share this report