Loading HuntDB...

Account takeover via insecure intent handling

Medium
B
Basecamp
Submitted None

Team Summary

Official summary from Basecamp

By installing a malicious app on the same device where the Basecamp app is logged in, the attacker could obtain the Oauth2 token of the user logged in and take over his account.

Reported by fr4via

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Deserialization of Untrusted Data