Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by b8192051 - 05.03.2026
Last edited by cbay - 05.03.2026

FS#301 - I found a broken access control that allows users to read backup related information without access.

Steps to reproduce:

  1. Navigate to https://www.alwaysdata.com/en/register/ and create 2 accounts, accountA@gmail.com, accountB@gmail.com
  1. In accountA@gmail.com, invite accountB@gmail.com and grant it all access(this is so that we can capture the request to make testing easy.)
  1. Login to accountB@gmail.com, click on advanced → backup recovery, fille in the necessary details and submit while proxying the traffic through burp.
  1. In burp, identify the traffic to these endpoints and intercept.
Closed by  cbay
05.03.2026 11:41
Reason for closing:  Invalid
Admin
cbay commented on 05.03.2026 11:15

Hello,

You say "without access" in the summary, but "grant it all access" in your details, so I'm not sure I follow. If you grant all permissions to someone, then he gets all accesses.

Kind regards,
Cyril

Hello team, since this is my first time submitting a report on this platform, I mistakenly sent it without completing the report. Please ignore it and read it from the new one that I submitted here.

Since you have already replied to the message, I am submitting a new one.

Sorry for the inconvenience caused.

Hello team, this is the link to the new report submitted with step by step instructions on how to reproduce it.

https://security.alwaysdata.com/task/302

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing