Dialog security vulnerability

BC_Dilum

Well-known member
  • Mar 2, 2008
    17,924
    1,190
    113
    192.168.1.1
    Today I found a severe security vulnerability in Dialog online portal login. One of their public APIs exposing login url for any user.

    I attached a screenshot of the API but for ethical reasons I blocked some part of the url

    Because of this issue I can log into user accounts who are trying to log into Dialog portal at the moment

    Screenshot 2020-06-05 at 7.47.24 PM.png
     
    • Haha
    Reactions: Necromancer

    BC_Dilum

    Well-known member
  • Mar 2, 2008
    17,924
    1,190
    113
    192.168.1.1
    I sent a screen recording to Dialog Facebook page. But looks like it is not 1 hour fix. They need to change entire login process