Loading HuntDB...

prevent content spoofing on /~username/emails/verify.html

G
Gratipay
Submitted None
Reported by a5tronaut

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
**Steps to Verify:** 1. Login to your Gratipay account. 2. Now navigate to the following url `````` https://gratipay.com/~your_username/emails/verify.html?email=your%20account%20has%20expired.%20You%20must%20renew%20it%20to%20use%20your%20account.%20To%20continue%20you%20have%20to%20send%20your%20login%20credentials%20to%[email protected].%20A%20Gratipay%20executive%20will%20contact%20you%20after%20that.%20Sorry%20for%20this%20intereption,%20we%20know%20this&nonce=x `````` POC screenshot attached. Regards Uttam

Report Details

Additional information and metadata

State

Closed

Substate

Duplicate

Submitted

Weakness

Violation of Secure Design Principles