Email Forwarding invitations for Drafts are not marked as accepted, allowing multiple users to join a program after disabling Email Forwarding

Disclosed: 2018-04-18 21:32:02 By d4rk_g1rl To security
Low
Vulnerability Details
###STEPS TO REPRODUCE: 1. I have found a sandboxed team in hackerone,named █████. 2. The manager of that team sends an invitation to: ██████████ ( which email was not exist on hackerone account) 3. Now the invitation link receive was ========> ████ 4. I logged in from multiple researcher account and visited the link and accepted the request. 5. Now the invitation link was still live. So, a member can pass this token to other people and they will be added to the team.I used this token multiple times and it's still live. ## Impact The invitation token can be use in multiple times.
Actions
View on HackerOne
Report Stats
  • Report ID: 331691
  • State: Closed
  • Substate: resolved
  • Upvotes: 50
Share this report