Insufficient access control on all BCRM instances leading to the ability to create admin accounts using the API
Team Summary
Official summary from LY Corporation
[BCRM](https://bcrm-doc.line.me/) is a service that helps manage and analyze your LINE Official Account, and provide useful insights. Due to insufficient access control checks in the /admins API endpoint, it was possible for an attacker to create admin accounts. These accounts are "super"-admin accounts meant for internal use only. The endpoint has to be publicly available in order for customers to invite new users as admins, but due to insufficient checks, it was also possible to create "super"-admin accounts. After receiving the report, we quickly investigated and made sure no suspicious accounts existed and that there had been no malicious activity. We would like to thank @j0eii for his clear proof of concept and how he demonstration of the potential impact of this issue, without affecting our end users.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic