Account Takeover using Improper Authorization in “Check Availability” Feature
好的,我现在要帮用户总结这篇文章的内容。用户的要求是用中文总结,控制在100字以内,而且不需要以“文章内容总结”或者“这篇文章”这样的开头,直接写描述即可。 首先,我需要仔细阅读文章内容。文章主要讲的是一个最近解决的报告,这个报告是提交给一个私人程序的。这个程序是一个应用程序,用于招聘专业人士提供各种服务,比如家庭清洁、地毯清洁、水管工、油漆工和承包商等。 接下来,文章提到了受害者账户的情况。任何人都可以通过电子邮件地址注册账户,而受害者没有提供电话号码,账户是通过电子邮件注册的。应用程序上有专业人士的个人资料,包括水管工、承包商、电工等。这些专业人士的信息是可以被未认证的用户查看的。 然后,在检查可用性的过程中,用户可以输入受害者的电子邮件地址,而这个账户已经存在了。这可能涉及到隐私问题或者安全漏洞。 现在我要把这些信息浓缩到100字以内。重点包括:应用程序的功能、注册方式、未认证访问专业人士资料以及潜在的安全问题。 可能的结构是:描述应用程序的作用,注册方式和存在的安全问题。 比如:“文章描述了一个招聘服务平台的应用程序漏洞。用户可通过邮箱注册账户,并查看未认证的专业人士资料。攻击者可利用现有邮箱进行操作,引发潜在安全风险。” 这样既涵盖了主要信息,又控制在了字数范围内。 </think> 文章描述了一个招聘服务平台的应用程序漏洞。用户可通过邮箱注册账户,并查看未认证的专业人士资料。攻击者可利用现有邮箱进行操作,引发潜在安全风险。 2026-2-11 13:46:55 Author: infosecwriteups.com(查看原文) 阅读量:0 收藏

Ronak Patel

Hello Guys!!!!

Hope you are doing Great.

This article is about recently resolved report, which was submitted to private program. which is application for hiring professionals for different kind of services like House cleaning , carpet cleaning , plumbers, Painters,Contractors.

Press enter or click to view image in full size

Victim Account

As seen above anyone can sign up through email address in application and his account would be created. As seen in above image victim has not supplied his phone number.Account is registered using email only.

Application has profile of the professionals who provides services like plumber, contractors,electricians and more. There is functionality to check availability of such professional unauthenticated.

So any user without any kind of authentication go to any professional’s profile which contains his ratings and feedback,can start the flow to check availability of that professional as seen below

Check Availability

While go through this flow we can supply victim’s email which account already exist as below


文章来源: https://infosecwriteups.com/account-takeover-using-improper-authorization-in-check-availability-feature-4f9f65098853?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh