Vulnerabilities tagged "account-takeover"

HubSpot Full Account Takeover in Bug Bounty

A lot of wrong turns, eventually leading to some parameter brute forcing and the discovery of an `href` param when submitting a Forgot Password request.The `href` value would be used to craft the forgot password link with the actual token appended to it that is reflected in the Forgot Password email...
 
1
2