Access to alerta.khanacademy.org leak sensitive data
Critical
K
Khan Academy
Submitted None
Actions:
Reported by
myominthu_sec
Vulnerability Details
Technical details and impact analysis
Hi ,
I found to access https://alerta.khanacademy.org/ using signup bypass.That leak access to sensitive data of khanacademy.org
Step To Reproduce:
1. Go to https://alerta.khanacademy.org/#/signup
2. Inspect Q and remove ng-hide
{F1121291}
3. You got Signup Form. Signup account using [email protected] mail.
{F1121292}
4. When you successfully signup,You access alerta.khanacademy.org without confirm email.
{F1121297}
If you not login direct .
1. Go to alerta.khanacademy.org/#/login.
2. Inspect Q and remove ng-hide
{F1121293}
3. Login with your register info.
{F1121294}
## Impact
Attacker can access alerta dashboard
Thanks,
@nightmare_msf
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic