Loading HuntDB...

Insufficient access control on all BCRM instances leading to the ability to create admin accounts using the API

High
L
LY Corporation
Submitted None

Team Summary

Official summary from LY Corporation

[BCRM](https://bcrm-doc.line.me/) is a service that helps manage and analyze your LINE Official Account, and provide useful insights. Due to insufficient access control checks in the /admins API endpoint, it was possible for an attacker to create admin accounts. These accounts are "super"-admin accounts meant for internal use only. The endpoint has to be publicly available in order for customers to invite new users as admins, but due to insufficient checks, it was also possible to create "super"-admin accounts. After receiving the report, we quickly investigated and made sure no suspicious accounts existed and that there had been no malicious activity. We would like to thank @j0eii for his clear proof of concept and how he demonstration of the potential impact of this issue, without affecting our end users.

Reported by j0eii

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic