Account takeover via insecure intent handling
Medium
B
Basecamp
Submitted None
Team Summary
Official summary from Basecamp
By installing a malicious app on the same device where the Basecamp app is logged in, the attacker could obtain the Oauth2 token of the user logged in and take over his account.
Actions:
Reported by
fr4via
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Deserialization of Untrusted Data