Swezy on X: "🚨Discovered a vulnerability on https://t.co/N8kXoHba7G that allowed UNAUTHORIZED PASSWORD RESETS via the endpoint:
🔭/api/auth/trigger-reset-password-email
By combining a crafted CSRF token with an email reset token, I could:"
🚨Discovered a vulnerability on whitepages.com that allowed UNAUTHORIZED PASSWORD RESETS via the endpoint:
🔭/api/auth/trigger-reset-password-email
By combining a crafted CSRF token with an email reset token, I could:
🚨Discovered a vulnerability on whitepages.com that allowed UNAUTHORIZED PASSWORD RESETS via the endpoint:
🔭/api/auth/trigger-reset-password-email
By combining a crafted CSRF token with an email reset token, I could:
• Reset any user's password. (📸Screenshot 1)
• Access full personal details (full name, phone number, etc.). (📸Screenshot 2) - all with just their email address, by the way 😬
I responsibly reported the issue the second I found it.
⏳ Waited 2 weeks. (📸Screenshot 1)
🙅 No response.
🧱 Silent patch.
😶 Not even a "thank you."
(📸Screenshot 2)
Responsible disclosure deserves respect, not silence.