Loading HuntDB...

Exposed CDN access token allows modification of all newly uploaded Snapmatic photos

Medium
R
Rockstar Games
Submitted None

Team Summary

Official summary from Rockstar Games

In this report, the researcher reported an exposure of CDN access token that allows an attacker to modify newly uploaded photo in GTA5 Snapmatics. The access token retained validity for a brief interval subsequent to the upload process, thereby providing a window of opportunity for content modification. This issue has been resolved by removing CDN fields from the response.

Reported by bugstar

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic