Loading HuntDB...

' Full Account Takeover ' at █████

Critical
M
Mars
Submitted None

Team Summary

Official summary from Mars

A severe vulnerability is identified in the login functionality of a website belonging to Mars. An unauthorized actor can manipulate the server's response from the █████████████ endpoint to gain unauthorized access to any user account on the platform, leading to a full account takeover. The attacker can achieve this by intercepting the login request, modifying the server's response to indicate a successful login, and setting a cookie with the target user's ID. This exploit does not require knowledge of the victim's email address or password.

Reported by 0xs4m

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic