Perform substring search for emails even if Workplace admin hides email profile field.
Description:
Attack can perform substring search for emails even if Workplace admin hides email profile field.
As admin From the Admin Panel, goto Settings >> Profile fields >> on Email field Turn visibility off.
Bug 1: Reward $1000
Login as non-admin user in Workplace4Android
- Connect workplace installed mobile to PC with usb debugging enabled
- Run ADB command from terminal:
1
adb shell am start -d “fb-work://at_work_company_dashboard_manage_people” - Workplace launches
Manage Peopleactivity In search box perform any email search query like
@yahoo.com@gmail.comor random full email in result user associated with searched email will appears.- In this dashboard we can also get
Claimed/Deactivated/Invitedusers.
Bug 2: Reward $1000 In workplace web As non-admin user
- Goto Directory >> Search box
- In search box perform any email search query like
@yahoo.com@gmail.comor random full email in result user associated with searched email appears as result.
Timeline:
Bug 1:
- 05/October/20: Submitted
- 14/October/20: Resolved
Bug 2:
- 18/August/20: Submitted
- 16/September/20: Resolved
This post is licensed under CC BY 4.0 by the author.