exploitable weaknesses in functionality

Disclosed by
asad_anwar
  • Engagement Indeed
  • Disclosed date over 3 years ago
  • Points 10
  • Priority P3 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by asad_anwar

Hello,
I found vulnerability in functionality which could lead to exploitable by any low privilege user .

In "https://ads.indeed.com/account/secondary-accounts" there is an options for disable or enable the user right, which was assign by main/super admin

Disable function is not working correctly which allow low user to enable his/her privileges.

Activity