bypass Claudflare access crm.mautic.com

Disclosed: 2019-04-05 09:25:33 By b4a1d31dd4acbccc47b8072 To unikrn
None
Vulnerability Details
Hi @unikrn! Hello, I see that when you switch to the crm,unikrn.com, login attempts are filtered by Claudflare Access to avoid brute-force account attacks, but we can ByPASS Claudflare access. Example: https://crm.unikrn.com/oauth/v2/authorize_login ## Impact having accounts, we can easily get into the admin area
Actions
View on HackerOne
Report Stats
  • Report ID: 507012
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report