Privilege escalation allows to use iframe functionality w/o upgrade

Disclosed: 2019-06-05 08:03:55 By muon4 To infogram
Unknown
Vulnerability Details
Hello team! I've found a privilege escalation issue which allows to set iframes to the projects w/o upgrading. ### Steps to reproduce - Login - Navigate to the project - Choose `integrations` and click the `IFrame` - See that you'll get `upgrade now` notification {F501019} - Inspect the page with developer tool and choose the `upgrade` from `IFrame` icon - Delete the `data-upgrade="true"` part {F501023} - Click the `IFrame` and see that you are able to add iframe to the page w/o upgrade {F501024} If you need any information please let me know. Cheers! ## Impact Users can use functionalities without paying
Actions
View on HackerOne
Report Stats
  • Report ID: 594080
  • State: Closed
  • Substate: resolved
  • Upvotes: 32
Share this report