Tampering the mail id on chatbox
None
Vulnerability Details
hi sir , i found a vulnerability i.e tampering the data .
steps to reproduce
1) login to https://app.legalrobot-uat.com
2) open https://app.legalrobot-uat.com/account
3) at right side bottom corner , there is a chat symbol.
4) just enter the message there , and capture the request using burpsuite and send the request in to repeater tab , after that change the maild owner mail id to some other xxxx mail id and click on send
5) at the response tab we will get the response 200 ok.
Thank you sir , hope you understand . here is the poc pics,
Actions
View on HackerOneReport Stats
- Report ID: 260239
- State: Closed
- Substate: informative
- Upvotes: 1