read and message other user's messages
Critical
Vulnerability Details
go to your account's chat page, stop the request and change the reddit session parameter, now leave the request and you will be able to access the test account's chat screen
send the request to the repeater change the reddit session parameter and send it then you will see the return result is 200
show reply in browser and copy and paste the address into your browser you will access the chat page of your test account
## Impact
other users' chat screen can be accessed
and message can be sent
Actions
View on HackerOneReport Stats
- Report ID: 1744264
- State: Closed
- Substate: not-applicable
- Upvotes: 5