
Summary: An attacker is able to login to any email account (that doesn't belong to him) through using the OAuth functionality (https://staging.genasystech.co.uk/d2c-api/v1/account/login/provider) Steps To Reproduce: Register an account with an email and verify it using the one time code that is asked upon registration, I registered ██████ Go to https://staging.genasystech.co.uk/d2c/, as this will log you out if you're logged in Open Burp Suite and go to the log in page, make sure you have intercept requests 'on' Choose 'Sign-in using Google' Click 'Forward' on all requests until you can select a Gmail account. Then select one belonging to a different email (I chose ████████) Keep forwarding the request until you see the request like below: ``` POST /d2c-api/v1/account/login/provider HTTP/1.1 Host: staging.genasystech.co.uk User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Firefox/60.0 Accept: application/json Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Referer: https://staging.genasystech.co.uk/d2c/ Content-Type: application/json-patch+json Content-Length: 1344 Cookie: ASP.NET_SessionId=thu1bqkkwmat143llht2ese1 Connection: close...
SOCIAL SHARE CARD GENERATOR