Broken Access Controls

Disclosed: 2021-02-09 10:24:54 By lucasandracoli To acronis
None
Vulnerability Details
The End Point `notary.acronis.com` Blocks access to the panel if you are not an authenticated user. More is possible to access some functions of the panel by adding the .html at the end See Poc From Video Below ## Impact Broken access control vulnerabilities exist when a user can in fact access some resource or perform some action that they are not supposed to be able to access.
Actions
View on HackerOne
Report Stats
  • Report ID: 833735
  • State: Closed
  • Substate: resolved
  • Upvotes: 13
Share this report