Account members can re-add themselve after has been deleted by administrator
Low
M
Mavenlink
Submitted None
Actions:
Reported by
tolo7010
Vulnerability Details
Technical details and impact analysis
Reproduction:
=========
- As an administrator, invite an account members e.g: [email protected] via https://app.mavenlink.com/settings/account/members
- An invitation link sent to [email protected], as user1, open email inbox and click on the link, notice the link redirects to page url:
https://app.mavenlink.com/account_invitations/[token]/acceptances/new
- Note the above link.
- As user1, Click "Accept", the user has been added as an active member.
- As administrator, remove user1 from active member list.
- As user1, go to the noted link: https://app.mavenlink.com/account_invitations/[token]/acceptances/new,
and click "Accept", the user has been added to the group again.
## Impact
Any user can add himself after has been deleted from an administrator.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Privilege Escalation