Отправка писем с произвольным текстом/кликабельными ссылками любому зарегистрированному пользователю с указанной почтой, зная только steamid
Critical
C
CS Money
Submitted None
Team Summary
Official summary from CS Money
Using a third-party service `GetResponse` used on the project and the 2FA deactivation functionality combined, a hacker found a way to send **arbitrary text** to **any** user, knowing only the victim's SteamID. *The vulnerability relied on:* 1. Invalid cookie management in request; 1. No additional validation for email ownership.
Actions:
Reported by
libneko
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Reliance on Cookies without Validation and Integrity Checking in a Security Decision