Impersonation in Sequential Messages vulnerability

Post Reply
Shane1145
Posts: 1836
Joined: Wed Sep 25, 2024 2:31 pm

Impersonation in Sequential Messages vulnerability

Post by Shane1145 »

Sequential messages posted by the same user on the same date are rendered without repeating the author information and timestamp.
An adversary can use customClass or className message attributes to hide the initial message of a new author from the timeline, so that the second message appears to be written by a differnet author.


https://hackerone.com/reports/1379645
Post Reply