InfoSec Write-ups
Read post

Account Takeover Across Multiple Programs via Featurebase Integration

A bug bounty researcher discovered an IDOR vulnerability in Featurebase, a third-party feedback platform used by many organizations. By manipulating the userId field in a POST /api/v1/user/identify request, an attacker could change a victim's email address and then trigger a password reset to fully take over their account. A secondary attack path also exposes access tokens via account modification requests. Featurebase declined to fix the issue directly, instead pointing site owners to their JWT-based secure installation option as a mitigation.

    #authentication
Yesterday•3m read time•From infosecwriteups.com
Post cover image
Table of contents
Get JEETPAL’s stories in your inboxAnd here’s something special for you! 🚨
49 Impressions
InfoSec Write-ups's image
InfoSec Write-ups

InfoSecWriteUps' platform is dedicated to providing insights and resources for cybersecurity profes...

977 Followers

•

4.1K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard