Account members can re-add themselve after has been deleted by administrator

Disclosed: 2018-05-03 18:36:50 By tolo7010 To mavenlink
Low
Vulnerability Details
Reproduction: ========= - As an administrator, invite an account members e.g: [email protected] via https://app.mavenlink.com/settings/account/members - An invitation link sent to [email protected], as user1, open email inbox and click on the link, notice the link redirects to page url: https://app.mavenlink.com/account_invitations/[token]/acceptances/new - Note the above link. - As user1, Click "Accept", the user has been added as an active member. - As administrator, remove user1 from active member list. - As user1, go to the noted link: https://app.mavenlink.com/account_invitations/[token]/acceptances/new, and click "Accept", the user has been added to the group again. ## Impact Any user can add himself after has been deleted from an administrator.
Actions
View on HackerOne
Report Stats
  • Report ID: 300881
  • State: Closed
  • Substate: resolved
  • Upvotes: 13
Share this report