Email Forwarding invitations for Drafts are not marked as accepted, allowing multiple users to join a program after disabling Email Forwarding
Low
Vulnerability Details
###STEPS TO REPRODUCE:
1. I have found a sandboxed team in hackerone,named █████.
2. The manager of that team sends an invitation to: ██████████ ( which email was not exist on hackerone account)
3. Now the invitation link receive was ========> ████
4. I logged in from multiple researcher account and visited the link and accepted the request.
5. Now the invitation link was still live.
So, a member can pass this token to other people and they will be added to the team.I used this token multiple times and it's still live.
## Impact
The invitation token can be use in multiple times.
Actions
View on HackerOneReport Stats
- Report ID: 331691
- State: Closed
- Substate: resolved
- Upvotes: 50