read and message other user's messages

Disclosed: 2023-05-18 13:56:34 By beksem35 To reddit
Critical
Vulnerability Details
go to your account's chat page, stop the request and change the reddit session parameter, now leave the request and you will be able to access the test account's chat screen send the request to the repeater change the reddit session parameter and send it then you will see the return result is 200 show reply in browser and copy and paste the address into your browser you will access the chat page of your test account ## Impact other users' chat screen can be accessed and message can be sent
Actions
View on HackerOne
Report Stats
  • Report ID: 1744264
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 5
Share this report