Loading HuntDB...

Account members can re-add themselve after has been deleted by administrator

Low
M
Mavenlink
Submitted None
Reported by tolo7010

Vulnerability Details

Technical details and impact analysis

Privilege Escalation
Reproduction: ========= - As an administrator, invite an account members e.g: [email protected] via https://app.mavenlink.com/settings/account/members - An invitation link sent to [email protected], as user1, open email inbox and click on the link, notice the link redirects to page url: https://app.mavenlink.com/account_invitations/[token]/acceptances/new - Note the above link. - As user1, Click "Accept", the user has been added as an active member. - As administrator, remove user1 from active member list. - As user1, go to the noted link: https://app.mavenlink.com/account_invitations/[token]/acceptances/new, and click "Accept", the user has been added to the group again. ## Impact Any user can add himself after has been deleted from an administrator.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Privilege Escalation