exploitable weaknesses in functionality

Disclosed by
asad_anwar's avatar
asad_anwar
  • Engagement Indeed
  • Disclosed date almost 3 years ago
  • Points 10
  • Priority P3 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by asad_anwar

Hello,
I found vulnerability in functionality which could lead to exploitable by any low privilege user .

In "https://ads.indeed.com/account/secondary-accounts" there is an options for disable or enable the user right, which was assign by main/super admin

Disable function is not working correctly which allow low user to enable his/her privileges.

Activity
  1. Kyle_indeed’s avatar
    Kyle_indeed Customer published the disclosure report

    ()

  2. asad_anwar’s avatar
    asad_anwar updated the disclosure summary

    ()

  3. asad_anwar’s avatar
    asad_anwar requested disclosure

    ()

  4. Jarvis’s avatar
    Jarvis Customer changed the state to Resolved

    ()

  5. asad_anwar’s avatar
    asad_anwar sent a message

    ()

  6. candydish_indeed’s avatar
    candydish_indeed Customer sent a message

    ()

  7. candydish_indeed’s avatar
    candydish_indeed Customer rewarded asad_anwar

    ()

  8. candydish_indeed’s avatar
    candydish_indeed Customer rewarded asad_anwar 10 points

    ()

  9. candydish_indeed’s avatar
    candydish_indeed Customer changed the state to Unresolved

    ()

  10. asad_anwar’s avatar
    asad_anwar sent a message

    ()

  11. candydish_indeed’s avatar
    candydish_indeed Customer sent a message

    ()

  12. asad_anwar’s avatar
    asad_anwar sent a message

    ()

  13. trim_bugcrowd’s avatarbugcrowd logo
    trim_bugcrowd sent a message

    ()

  14. trim_bugcrowd’s avatarbugcrowd logo
    trim_bugcrowd changed the severity to P3

    ()

  15. trim_bugcrowd’s avatarbugcrowd logo
    trim_bugcrowd changed the state to Triaged

    ()

  16. asad_anwar’s avatar
    asad_anwar sent a message

    ()

  17. asad_anwar’s avatar
    asad_anwar resolved a blocker for Bugcrowd Operations by verifying credentials

    ()

  18. asad_anwar’s avatar
    asad_anwar sent a message

    ()

  19. asad_anwar’s avatar
    asad_anwar sent a message

    ()

  20. trim_bugcrowd’s avatarbugcrowd logo
    trim_bugcrowd created a blocker on the researcher to verify credentials

    ()

  21. trim_bugcrowd’s avatarbugcrowd logo
    trim_bugcrowd sent a message

    ()

  22. asad_anwar’s avatar
    asad_anwar resolved a blocker for Bugcrowd Operations by providing information

    ()

  23. asad_anwar’s avatar
    asad_anwar sent a message

    ()

  24. asad_anwar’s avatar
    asad_anwar sent a message

    ()

  25. trim_bugcrowd’s avatarbugcrowd logo
    trim_bugcrowd created a blocker on the researcher to provide information

    ()

  26. trim_bugcrowd’s avatarbugcrowd logo
    trim_bugcrowd sent a message

    ()

  27. asad_anwar’s avatar
    asad_anwar resolved a blocker for Bugcrowd Operations by providing information

    ()

  28. asad_anwar’s avatar
    asad_anwar sent a message

    ()

  29. asad_anwar’s avatar
    asad_anwar sent a message

    ()

  30. asad_anwar’s avatar
    asad_anwar sent a message

    ()

  31. trim_bugcrowd’s avatarbugcrowd logo
    trim_bugcrowd created a blocker on the researcher to provide information

    ()

  32. trim_bugcrowd’s avatarbugcrowd logo
    trim_bugcrowd sent a message

    ()

  33. asad_anwar’s avatar
    asad_anwar created the submission

    ()