image dsbw

Extract all users emails end with( @company.com ) with names in DB of Company users



Published il y a 3 mois

image de Extract all users emails end with( @company.com ) with names in DB of Company users

Hi, This is DevSecure Team ,we specialize in uncovering hidden vulnerabilities that pose real-world risks to modern web applications.
All vulnerabilities shared in these write-ups are fully redacted — any company names, domains, or sensitive details are replaced with placeholders such as company.com. Each finding was responsibly disclosed through the Intigriti platform and has been verified and resolved by the affected vendor.

Every post represents our commitment to ethical hacking, responsible disclosure, and continuous learning, helping organizations strengthen their defenses while contributing to a safer global cybersecurity ecosystem.

i found a method to get all emails with @company.com in company admin db
the method is in 2 steps after login as admin
1/ go to this endpoint
with PUT request
admin.company.com/admin/services/user/settings

[{"idUser":Here_Company_User_Id,"validToDate":"2023-03-06T00:00:00.000Z","operation":"1"}]

with intruder you could do this and extract all of them
just for prof of concept
this is a list of valid ids wich i found :

1
2
19
20
...
824050

wich you could use

and you can download the attached file wich you can get more idUsers of @company.com emails

2/ go tho this endpoint you will get the emails with first and last names
admin.company.com/admin/user/settings/userlist?usersWithNoRole=false

Impact
information disclosure

Platform : Intigriti
Timeline :
Reported: 05/03/2023
Triaged: 07/03/2022
Accepted & paid: 07/03/202
Bounty: €1,000
https://app.intigriti.com/profile/merroun

More Articles You May Like

Blog Image
IDOR Get any Customer all invoices

1/ create new company and login 2/ go to services-api.company.com/customers/{UUID}/invoices?invoiced=false 3/ change UUI...

Read More →
Blog Image
get personal information of workers

1/ go to this endpoint https://company.com/search?p_p_lifecycle=0&saveLastPath=true&q=cv&type=com.liferay.document.libra...

Read More →
Blog Image
Export Subscription Application Instance List ( with internal host ) and SupportCompanySearchCustomers

Export Support Company Search Subscription Application Instance List and Support Company Search Customers Tunnels List...

Read More →