oauth misconfigration lead to account takeover

Disclosed: 2023-05-18 13:53:13 By greymanx1 To reddit
Unknown
Vulnerability Details
## Summary: misconfigration in aouth 2.0 login with google account in "accounts.reddit.com" ## Impact: misconfigration leads to account takeover ## Steps To Reproduce: 1. go to "https://accounts.reddit.com/". 2. and login with your google account. 3. after login, logout from your account. 4. after logout go to "https://accounts.reddit.com/account/register/" and register with email you signed in before in google account oauth. 5. as like you see it's created a new account * [attachment / reference] ## Impact attacker can login with any user's email thats lead to account takeover
Actions
View on HackerOne
Report Stats
  • Report ID: 1815463
  • State: Closed
  • Substate: informative
  • Upvotes: 6
Share this report