Source |
The Hacker News |
Identifiant |
8643852 |
Date de publication |
2025-01-28 19:32:00 (vue: 2025-01-28 15:12:10) |
Titre |
OAuth Redirect Flaw in Airline Travel Integration Exposes Millions to Account Hijacking |
Texte |
Cybersecurity researchers have disclosed details of a now-patched account takeover vulnerability affecting a popular online travel service for hotel and car rentals.
"By exploiting this flaw, attackers can gain unauthorized access to any user’s account within the system, effectively allowing them to impersonate the victim and perform an array of actions on their behalf – including
Cybersecurity researchers have disclosed details of a now-patched account takeover vulnerability affecting a popular online travel service for hotel and car rentals.
"By exploiting this flaw, attackers can gain unauthorized access to any user’s account within the system, effectively allowing them to impersonate the victim and perform an array of actions on their behalf – including |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
access account actions affecting airline allowing any array attackers behalf can car cybersecurity details disclosed effectively exploiting exposes flaw gain have hijacking hotel impersonate including integration millions now oauth online patched perform popular redirect rentals researchers service system takeover them travel unauthorized user’s victim vulnerability within |
Tags |
Vulnerability
|
Stories |
|
Move |
|