OAuth misconfiguration found on https://wemedia.opera.com

Disclosed by
h_-_cker
  • Engagement Opera Public Bug Bounty
  • Disclosed date over 4 years ago
  • Reward $150
  • Priority P4 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by h_-_cker

When third party authentication cookies are not properly invalidated after logout from the app as well as authentication server, it is OAuth misconfiguration leading to account squatting on victim's device. One such instance was found on Wemedia application of Opera.

Activity