Loading HuntDB...

Site wide CSRF affecting both job seeker and Employer account on glassdoor.com

Critical
G
Glassdoor
Submitted None

Team Summary

Official summary from Glassdoor

Summary: I have found an issue which enables an attacker to do CSRF attacks on all actions on both job seeker and employer account on www.glassdoor.com. Attacker is able to get a CSRF token from the server, which can be used to do CSRF attacks on any logged in victim on both types of glassdoor accounts. Attacker can do an attack to invite a new user as admin on a victim's employer account which leads to account takeover. For job seeker account also, attacker can perform all actions on victim's account, like: adding salaries/reviews/photos , editing their profile, deleting CVs and all other possible actions. Bug Write-Up at : Witcoat Blog

Reported by ta8ahi

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-Site Request Forgery (CSRF)