A bug bounty researcher discovered an IDOR vulnerability in Featurebase, a third-party feedback platform used by many organizations. By manipulating the userId field in a POST /api/v1/user/identify request, an attacker could change a victim's email address and then trigger a password reset to fully take over their account. A secondary attack path also exposes access tokens via account modification requests. Featurebase declined to fix the issue directly, instead pointing site owners to their JWT-based secure installation option as a mitigation.
49 Impressions