CSRF to Account Take Over Bug

Disclosed: 2014-09-08 12:13:49 By defmax To irccloud
Unknown
Vulnerability Details
Hello Sir This is N B Sri Harsha I Have Found An CSRF to Account take over bug effected url :- https://www.irccloud.com/chat/user-settings I have wrote an html code and uploaded it , please check that out u have to fill email address , there , and click on update settings U will get output as {"_reqid":0,"success":true} Thats It , the victims email address will be changed after that he goes to forgot password and changes the password hope this security issue will be fixed soon
Actions
View on HackerOne
Report Stats
  • Report ID: 7116
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report