image dsbw
Responsible Disclosure

External Guest Can View all projects in the company

Merroun Lahcen — DevSecure Published il y a 6 mois
image de External Guest Can View all projects in the company

Hi, I'm Merroun Lahcen from DevSecure — we specialize in uncovering hidden vulnerabilities that pose real-world risks to modern web applications.


All vulnerabilities shared in these write-ups are fully redacted — any company names, domains, or sensitive details are replaced with placeholders such as company.com. Each finding was responsibly disclosed through the Intigriti platform and has been verified and resolved by the affected vendor.


Every post represents our commitment to ethical hacking, responsible disclosure, and continuous learning — helping organizations strengthen their defenses while contributing to a safer global cybersecurity ecosystem.

in this company you could invite a Guest user and affect to him a project to work in but this vulnerability make a Guest user able to View all projects in the company without any invitation to any project and thats a clear Broken Access control issue POC: 1/ login with owner user role click on invite user chose external ( Guest ) from there you can read Guests can only read, upload, and download documents in projects which they are invited to. 2/ get your jwt token for the invited guest user with post request include guest credentials to https://api.company.com/auth/token 2/ without any invitation to any project you can view all projects in the company from this endpoint https://api.company.com/api/projects Platform : Intigriti Timeline : Reported: 20/11/2022 Triaged: 21/11/2022 Accepted & paid: 21/11/2022 Bounty: €150