Загрузка видео...
Не удалось загрузить видео
Integrity flow vulnerability in "microsoft teams" poll 3000$ bounty Sometimes, overlooked isuue can create significant vulnerability. In the "displayname" field, we send the name of the person we want the message to be send. #bugbounty
11,998 просмотров • 2 лет назад •via X (Twitter)
Комментарии: 10

#AmaN 🔥2 лет назад
Have you created poll with another user id ?

Moslem Haghighian2 лет назад
Yes that's right

#AmaN 🔥2 лет назад
Because I didn’t understand properly

Damanpreet Singh🇮🇳🐐2 лет назад
@v3d_bug 66897 🌜, congratulations 🎉

🦇 ©2 лет назад
So you created a poll on behalf of user

Verneet2 лет назад
is it fixed?

Moslem Haghighian2 лет назад
Yes, according to the rules, you have to wait until the bug is fixed, that's why I published this vulnerability after a few months of delay.

CoinbasePro2 лет назад
impact?

CoinbasePro2 лет назад
bro you just intersept and change the name so where is impact...?

Moslem Haghighian2 лет назад
In this vulnerability, it was possible to change the name to your ID and send messages or polls in the group instead of you. So identity spoofing happens because I poll with another person's ID.


