
Summary: The password reset link of user account on critical sixt+ domain/product can be obtained using the page https://www.sixt.com/php/profile/login_or_password_forgotten. This page requires email address and surname/lastname of the user to send password reset link on email. This link contains the reset key/token in 'k' parameter. Cross domain token leakage via Referer header vulnerability exists on this page https://www.sixt.com/php/profile/login_or_password_forgotten. The sensitive password reset token is exposed to third party social media sites i.e. Youtube, Facebook, Twitter, Instagram and Snapchat. Steps To Reproduce: Get a password reset link on email and load the page on browser such as https://www.sixt.com/php/profile/login_or_password_forgotten?k= On password reset page, click on social media links and capture the requests using Burp. You may observe that full password reset link is exposed to third party sites via Referer header. Supporting Material/References: Screenshots of Burp captured requests are attached here as PoC. Impact Another existing vulnerability is that the password reset link is not expired after change of password. The link remains valid for 48 hours and could be used multiple times to change password of user account on critical sixt+ domain/product. In the environment where the password reset link is not expired after change of password, the leakage of token to third-party hosts become more sensitive vulnerability as it has direct impact...
SOCIAL SHARE CARD GENERATOR