app.lemlist.com : Admin Panel Access

Disclosed: 2020-07-23 13:20:43 By omarelfarsaoui To lemlist
None
Vulnerability Details
hi team, ### Steps To Reproduce: While doing some analyse for javascript files in [app.lemlist.com](https://app.lemlist.com) i found interesting endpoints . is the **admin** panal and is not protected , any normal user can access the panel . ## Steps To Reproduce: (Add details for how we can reproduce the issue) 1. Log into your account. 1. visit on of the link below. https://app.lemlist.com/admin https://app.lemlist.com/admin/i18n https://app.lemlist.com/admin/mailboxes/123 ## Impact Incorrect access restriction to the authorized interface. Best Regards, @omarelfarsaoui
Actions
View on HackerOne
Report Stats
  • Report ID: 937921
  • State: Closed
  • Substate: informative
  • Upvotes: 5
Share this report