Improper ACL in Message Starring security issue

Post Reply
Shane1145
Posts: 1854
Joined: Wed Sep 25, 2024 2:31 pm

Improper ACL in Message Starring security issue

Post by Shane1145 »

Description: Room access validation is performed on user provided data. In absence of a check whether a Message is in a certain room, attackers can provide an unrelated Room ID where they have access to (e.g. general) to then star an arbitrary message.


https://hackerone.com/reports/1060837
Post Reply