Loading HuntDB...

[uchat.uberinternals.com] Mattermost doesn't check Origin in Websockets, which leads to the Critical Inforamation Leakage.

Critical
U
Uber
Submitted None

Team Summary

Official summary from Uber

Thanks for the report and participation in our program, @kxyry!

Reported by kxyry

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$2000.00

Submitted

Weakness

Cross-Site Request Forgery (CSRF)