Cookie Consent by Free Privacy Policy Generator 📌 Reddit: IDOR allows an attacker to modify the links of any user

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 Reddit: IDOR allows an attacker to modify the links of any user


💡 Newskategorie: Sicherheitslücken
🔗 Quelle: vulners.com


image
Hi team! I found an IDOR which allows to modify the links of any user. Users can put their custom links or social media links on their profile, ex: {F1855366} To reproduce this: Replicate the following request by replacing it with your own authentication headers: You must also put in the body of the request, in the parameter "username" the username that you want, you can try my username: "criptexhackerone1". This request will return in the response the links of any user profile with the "id" of each link. ``` POST / HTTP/2 Host: gql.reddit.com Content-Length: 62 Sec-Ch-Ua: ".Not/A)Brand";v="99", "Google Chrome";v="103", "Chromium";v="103" X-Reddit-Loid: * * * * * * * * * * * * * * * * Sec-Ch-Ua-Mobile: ?0 Authorization: Bearer * * * * * * * * * * * * * * * * * * * * * Content-Type: application/json User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.0.0 Safari/531.36 X-Reddit-Compression: 1 X-Reddit-Session: * * * * * * * * * * * * * * * * * Sec-Ch-Ua-Platform: "Windows" Accept: /* Origin: https://www.reddit.com Sec-Fetch-Site: same-site Sec-Fetch-Mode: cors Sec-Fetch-Dest: empty Referer: https://www.reddit.com/ Accept-Encoding: gzip, deflate Accept-Language: es-ES,es;q=0.9,en-US;q=0.8,en;q=0.7,bs;q=0.6,ja;q=0.5 {"id":"11a239b07f86","variables":{"username":"***"}} ``` When you get some "id" save it. In the next request you have to put in the request body, in... ...



📌 Reddit: IDOR allows an attacker to modify the links of any user


📈 95.56 Punkte

📌 Automattic: [IDOR] Attacker user can Approve/Decline AFK on the behalf of other users


📈 38.44 Punkte

📌 Nextcloud: Authentication bypass in Global Site Selector allows an attacker to log in as any user


📈 38.09 Punkte

📌 Reddit: Getting access of mod logs from any public or restricted subreddit with IDOR vulnerability


📈 37.56 Punkte

📌 Nextcloud: IDOR allows me to mark devices of another user for remote wipe out


📈 34.16 Punkte

📌 Reddit: Can use the Reddit android app as usual even though revoking the access of it from reddit.com


📈 33.44 Punkte

📌 Is it safe for reddit to be embedding links as iframes on old.reddit.com?


📈 32.6 Punkte

📌 Bugtraq: OSS-2016-02: Weak authentication in NXP Hitag S transponder allows an attacker to read, write and clone any tag


📈 32.3 Punkte

📌 Bugtraq: OSS-2016-02: Weak authentication in NXP Hitag S transponder allows an attacker to read, write and clone any tag


📈 32.3 Punkte

📌 Reddit: [accounts.reddit.com] Redirect parameter allows for XSS


📈 32.29 Punkte

📌 Phabricator: IDOR bug to See hidden slowvote of any user even when you dont have access right


📈 32.21 Punkte

📌 Do NOT ..For any reason .. modify the boot sector of a different physical drive - unless specified by the user.


📈 31.48 Punkte

📌 Beware while scrolling Reddit links on Google as a bug allows slurs to be added to URLs


📈 31.45 Punkte

📌 IDOR vulnerability in Reddit allowed attackers to perform mod actions


📈 29.52 Punkte

📌 An attacker can use rowhammer attacker to induce bit flips, thereby leaking the victim's secret data via a side channel.


📈 28.53 Punkte

📌 Attacker-Group-Predictor - Tool To Predict Attacker Groups From The Techniques And Software Used


📈 28.53 Punkte

📌 Yahoo fixes flaw allowing an attacker to read any user's emails


📈 28.1 Punkte

📌 Yahoo fixes flaw allowing an attacker to read any user's emails


📈 28.1 Punkte

📌 Yahoo Fixes Flaw Allowing an Attacker To Read Any User's Emails


📈 28.1 Punkte

📌 Yahoo Fixes Flaw Allowing an Attacker To Read Any User's Emails


📈 28.1 Punkte

📌 Simple Exploit Allows Attackers to Modify Email Content — Even After It's Sent!


📈 27.63 Punkte

📌 Slack: CSV export/import functionality allows administrators to modify member and message content of a workspace


📈 27.63 Punkte

📌 Automattic: IDOR in API applications (able to see any API token, leads to account takeover)


📈 26.41 Punkte

📌 Reddit reveals breach as attacker circumvents staff’s 2FA


📈 25.41 Punkte

📌 Reddit: Misconfigurated login page able to lock login action for any account without user interaction


📈 24.98 Punkte











matomo