Jump to content
dekeeu

Pinterest Vulnerability Exposed 70 Million Accounts

Recommended Posts

Posted

A critical vulnerability in Pinterest exposed 70 million accounts to potential hacking, according to security researcher Dan Melamed. The exploit allegedly allowed cyber-criminals to view the e-mail addresses of all Pinterest users.

By changing the /me/ part of a link with someone else's username, anyone was able to see that user's email address. According to the researcher, the flaw worked with any user on Pinterest and with any access token.

“With Pinterest surpassing over 70 million users and given the amount of high profile figures and brands that are using the site, such a flaw could have spelled disaster in the hands of a blackhat,” Dan Melamed said. “A hacker could have setup a bot to retrieve all of the email addresses from a list of users for spam or malicious purposes.”

The security researcher provided a simple fix for the Pinterest exploit. Checking the owner of the access token against the user whose information is being requested will prevent abuse. Melamed also published a video proof of concept for the Pinterest vulnerability.

The platform’s Security Team has said the exploit has been patched and added the security expert to their Heroes List together with two other researchers.

Sursa: Pinterest Vulnerability Exposed 70 Million Accounts

Blogul tipului: Dan Melamed Security Blog

POC:

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...