🟥Exploiting the Authentication Flow to Block Any User from Logging In/Resetting Password + An IDOR
A Vulnerable by Design Authentication System of a Very Famous Note-Taking App + Medium Severity IDOR
How does the Auth system work?
And here's the catch:
Another trick that I've found on the second request:
Python Script = Permanent Account Lockout
Attacker's POV

Victim's POV



The other bug - IDOR:


PreviousSome Privilege Escalations + Logic Flaws Led to (DoS, Organization Takeover & more)NextLogic flaw k1lled business messaging for all users
Last updated