Tabit - Arbitrary account modification. One of the endpoints mapped by the tiny URL, was a page where an adversary can modify personal details, such as email addresses and phone numbers of a specific user in a restaurants loyalty program. Possibly allowing account takeover (the mail can be used to reset password).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tabit | Tabit | * | 3.27.0 (excluding) |