Loading HuntDB...

Subdomain Takeover at creatorforum.roblox.com

High
R
Roblox
Submitted None
Reported by jackb898

Vulnerability Details

Technical details and impact analysis

Privilege Escalation
Hello. A few days ago, I was looking at Roblox subdomains, and I noticed an unusual one called creatorforum.roblox.com. Upon further investigation, I visited it and saw that creatorforum.roblox.com's CNAME was a nonexistant Discourse website. I immediately reported to [email protected], and eventually talked to Antek Baranski on the [email protected] email address. The issue has been fixed since reporting, but I was told to send a report here. If I had a Discourse account, I could've taken over the CNAME for creatorforum.roblox.com and then it would've been a full subdomain takeover on that subdomain. As mentioned earlier in the report, the issue has been resolved and as you can see the subdomain creatorforum.roblox.com no longer exists. Thanks, Jack

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Privilege Escalation