Unauthorised access to olx.in user accounts.
O
OLX
Submitted None
Actions:
Reported by
palashjhabak
Vulnerability Details
Technical details and impact analysis
Me and my friend, Ekansh, have found a severe security bug in your website, http://olx.in. Using this loophole one can gain full access to user accounts and perform actions like add/edit/delete ads and even delete the account itself.
Please find below attached video report and an accompanying pdf report showcasing the details of how we performed the attack, what are the possible impacts and an analysis of how easily and fast it can be achieved for many many users.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Authentication - Generic