Account members can re-add themselve after has been deleted by administrator
Low
Vulnerability Details
Reproduction:
=========
- As an administrator, invite an account members e.g: [email protected] via https://app.mavenlink.com/settings/account/members
- An invitation link sent to [email protected], as user1, open email inbox and click on the link, notice the link redirects to page url:
https://app.mavenlink.com/account_invitations/[token]/acceptances/new
- Note the above link.
- As user1, Click "Accept", the user has been added as an active member.
- As administrator, remove user1 from active member list.
- As user1, go to the noted link: https://app.mavenlink.com/account_invitations/[token]/acceptances/new,
and click "Accept", the user has been added to the group again.
## Impact
Any user can add himself after has been deleted from an administrator.
Actions
View on HackerOneReport Stats
- Report ID: 300881
- State: Closed
- Substate: resolved
- Upvotes: 13