Lucene search

K
openbugbountyGh05tPTOBB:1165970
HistoryMay 19, 2020 - 2:50 p.m.

costarricense.cr Improper Access Control vulnerability

2020-05-1914:50:00
Gh05tPT
www.openbugbounty.org
6

Open Bug Bounty ID: OBB-1165970

Following coordinated and responsible vulnerability disclosure guidelines of the ISO 29147 standard, Open Bug Bounty has:

&nbsp&nbsp&nbsp&nbsp&nbsp&nbspa. verified the vulnerability and confirmed its existence;
&nbsp&nbsp&nbsp&nbsp&nbsp&nbspb. notified the website operator about its existence.

Affected Website: costarricense.cr
Open Bug Bounty Program: Create your bounty program now. It’s open and free.
Vulnerable Application: Custom Code
Vulnerability Type: IAC (Improper Access Control) / CWE-284
CVSSv3 Score: 6.5 [CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N]
Disclosure Standard: Coordinated Disclosure based on ISO 29147 guidelines
Discovered and Reported by: Gh05tPT
Remediation Guide: OWASP Access Control Cheat Sheet
Export Vulnerability Data: Bugzilla Vulnerability Data
JIRA Vulnerability Data [ Configuration ]
Mantis Vulnerability Data
Splunk Vulnerability Data
XML Vulnerability Data [ XSD ]

Vulnerable URL:

![](data:image/png;base64, iVBORw0KGgoAAAANSUhEUgAAAiEAAAAjCAIAAADNIk3yAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAHp0lEQVR4nO3cX0hTbxgH8NfNbK4NnW5z6ixXUF1EBcmyMIouokLCKCHKMigMosIkJAfRqgtDMYiivCm0m+4iRhciQmCyC1vL/J+G6cwppYvVyeZwO7+LQ4d1/m1OTxs/vp+rPWfnfc/3PC/42o4rhaZpAgAAIANFogMAAMD/FvYYAACQC/YYAACQC/YYAACQC/YYAACQC/YYAACQS1LsMRaL5cOHD2IlLAeaCQAJlPg9pq+vLxwOb9u2TbCE5UAzASCxouwxExMTWq1W8C2/319fXy9Wxs7hcBw5ckSsXI64I3FINCHJSTczjvuKccjVq1fT09NbW1uXNHkcFwKAZEdLGh8f12g0sbwlcaY0q9Xa3t4uVi5H3JH4AoHAiszzj0k3M77+RG3F7OysQqHo6elZXFxc6uSsFVw7AEig1MTucNPT0yMjI/v27RMsk8fq1asTHWHJZGpm1FZQFKVWq/EBHQCQGJ/H3L9/32KxZGdnnz592u/3E0L8fn9hYSFFUSkpKa2trZHlvXv3tFptY2NjTk6OTqerrKz8/fu32MwOh+PAgQOrVq3il6FQqK6uLicnZ82aNeXl5XNzc4SQX79+XbhwwWAwFBQU3Lp1KxQKMQPfvn27Z88erVabn59/7NixoaEhTkLmnF27dqWnpxsMhvLy8qmpKfLnM5n6+nqDwZCbm/vkyROxI8yFBFMRQhYWFs6dO6fVatetW3fz5s1QKMSMampqslgsOp3u1KlTTOvEAgtOwu8YPwA/MKeZzAliK8JfXLYt/CFsK8Tubm5ujtN2sSWTvlAc2QAgCUXfYyiK6unpcTqd3d3dXq/3+vXrhJCMjIzh4WGNRhMIBCoqKiLLo0ePUhTV3d3tcrlcLpfb7W5oaBCbXOJhTENDQ0dHR0dHx8jISF5e3uDgICHkypUrXq/X7Xa3tbU5HI5Hjx4xJ5eWlp49e9bj8XR1dZWUlKhUKk5CQojb7a6qqpqZmenv7zebzZcuXWJvcHh4uL+/v6WlpaSkRPAISzAVIeT27dvz8/O9vb1tbW2dnZ3Nzc3MPL29vUzrPB6PzWZj5+EHFpuEQzCAYODIZoqtiODiSg+JPIF/d9nZ2Zy2iy1Z1AstJxsAJAvpj9LGx8cJIT9+/GBKp9O5fv169i3B5zHMEI/Hwxx/8eJFUVER89rj8RQWFrJDKIrSaDQ+n0+wNBqNbrc7Mszi4qJGoxkbG2NKh8NRXFxM07TP50tNTeU/J5D4TP/Tp08mk4lNy15U7Ag7Dz8VQ6/XUxTFvO7p6bFarZzWdXV1sa0TC8yfhH8hfgB+YPrvZoqtiPTiig2JXGXBu4tsl9iSccKvSDYASELRn8doNBr2k6K8vDyfzxd1iEqlKigoYF5v3rzZ4/Gww51OJ3tae3u71WrV6XT80u/3+3y+rVu3Rk779evXYDBosVjYmZkfNzqd7vjx48XFxfv378/LyysqKtq7dy8/1fv372trawcHB4PBYDgcDofD7A2yGcSOMARTEUK+f/8+OztbWFjIlOFwODU1lfzdOrPZzLZOMLDYJLEE4Afm9FZsRSQWV2xI5EUF7y6S2JJFkiMbACSJf/rMX6lU5ubmsmXUv1pWKpUxzvz8+fN379719/d7vd6amprdu3c/ePCAc05ZWdn58+ebm5tVKtWXL18OHjwY911wjgQCAYVC4XK52F1BoVAEg8ElBbbZbPxJYgzAt4J/Ag4AEDdZvoMZCAQmJyeZ1yMjI2vXruWfEwqFXr16xf4c5JQZGRlZWVmcL6gbjca0tLTPnz8z5fDwMPtbPyFkx44dlZWVdXV1T58+ffnyJedy375983q9N27c2LBhQ35+PvP8Y6kEUxFCcnNz1Wq1z+fL/yNyKxXDCRzLJGIBODjNJLGtCEccQ/iklyyx2QDgH4h/j9Hr9YFAYHR0VLCsqamZmpoaGBiw2+2lpaXsqIWFBeaF0+k0mUzspyickhBSXV1dVVXV19c3NTV1+fLlN2/eKJXKEydOVFdXT05OMjOfPHmSEDI0NHTo0KHXr1/Pzc1NTk4+fPhw+/btnEgGgyErK+vx48d+v390dNRut8d31/xUzPGKioqLFy8ODAxMT083NjbeuXNHYhKxwGKTsE2TCBCJ30wiviIS4hjCIbZknJtKSDYA+BekH9fwH+xnZmaypd1uV6vVLS0tkWVTU5NGo7l7967RaMzMzDxz5sz8/Dx/tmvXrtlsNnYqTknT9OLiYm1trV6vV6lUZWVls7OzNE1TFFVVVaXX681ms91uZ77lFwwG7Xb7xo0b09LSjEZjRUXFzMwMP2FnZ2dRUZFKpTKZTDU1NcyN8P8uQPqIYCqapgOBQHV1tdlsVqvVhw8fHhsbk2idWGD+JPw8/AD8wJxmMifwV0QiYdQhUceybwkuGWeeFckGAEkohabpld20JiYmtmzZ8vPnT+nTNm3a9OzZs507dwqWsBycZsa4IpHiGBKfZM4GAMuXsO/5f/z4UaKE5UAzASBJJP7/XQYAgP8r7DEAACCXlX8eAwAAwMC/YwAAQC7YYwAAQC7YYwAAQC7YYwAAQC7YYwAAQC7YYwAAQC7YYwAAQC7YYwAAQC7YYwAAQC7YYwAAQC7/AUqZ9OoZ0NcDAAAAAElFTkSuQmCC)

HTTP POST data:

![](data:image/png;base64, iVBORw0KGgoAAAANSUhEUgAAAiEAAAAjCAIAAADNIk3yAAAACXBIWXMAAA7EAAAOxAGVKw4bAAADmUlEQVR4nO3dvUsjWxjH8cl11ShjEYIviNGMjRYBIQS1tLKS1OILNoJgIZpCxErBShHUwj7+ARaDhVhLihCCLwgxhZoEI4gJqCPGYMwWwx3EbDLJOrPu9X4/1cyZ55zzVP6YkwQt+XxeAADABP98dQMAgG+LjAEAmIWMAQCYhYwBAJiFjAEAmIWMAQCYpYKMkSTp+PjYvFYAAN9MuRlzenr69vbW09NjajcAgO+k3IyRZdnr9RZ7GovFGhoayt+1/Pq5ubm6ujq/31/+4r+9FwDAWD/KrJNleWVlxahdOzo67u7udMtSqdTW1lY4HHa5XEZtDQD4Y8rKmJubm2g0OjAwYODGtbW1ujWKotTX13NABwD/UWWdlcmyPDg4WF1drZ47ra2tNTc322y2iYmJ5+dnrWxzc1OSJLvdPj4+fn9/L/x7TlVYr51fqRfr6+uSJNlsttHRUXWiIAipVMrpdCqKYrFY/H7/09PT1NRUY2Ojw+FYXl7O5XIfmjSqNwCAUcrNGO3DGEVRgsFgKBQKhULhcHh1dVUbPzo6CgQCwWAwmUwuLCyUrtcoinJycqJOjMfji4uL6rjdbo9EIqIoZjKZsbGxmZmZZDIZDof39/dlWd7e3i7s0/DeAACfktejKIooiul0Op/PX11dCYIQj8fVR7u7ux6PRxt/eHhQxwOBQGdnZ+l6URQLJx4eHqoTVVrZ6+urKIoXFxfquCzL/f39H/o0qjcAgFH032MODg56e3ttNpt6a7VaHQ6Het3d3R2Px9VrURS1r2+1tram0+nS9Zr3E9va2rSJ793e3mazWUmStHXUhPjA8N4AAJ+hnzGlv7UMAEAxOhmTy+X29vbeZ0wmk0kkEup1NBptb28vvUKl9b/U1NRUU1NzeXmp3kYiEafT+fm9DOkNAFCMTsYEAoGWlhbtkErl8/mur6/Pzs6WlpaGhoZ096i0vlBVVdXw8PDs7GwikVDXGRkZUR+9vLx8bW8AgGJ0fh9TeFAmiqLH43G73dls1uv1zs/Pl16h0vpiNjY2fD6f2+22Wq2Tk5PT09OCIMRiMZfL9fj4+LW9AQB+yZLP50s87urq2tnZ6evrU28//E3XVWn9Z/zNvQHA/5POe8z5+fmf6QMA8P3w/2MAAGYhYwAAZtH5PAYAgN/GewwAwCxkDADALGQMAMAsZAwAwCxkDADALGQMAMAsZAwAwCxkDADALGQMAMAsZAwAwCw/AT7F7VtomalnAAAAAElFTkSuQmCC)

Research’s Comment:

![](data:image/png;base64, iVBORw0KGgoAAAANSUhEUgAAAiEAAAAjCAIAAADNIk3yAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAG+UlEQVR4nO3cUUhTXxwH8Ls5bM6t3NpMbaEWRA8hPUhoGEEPYRIh1ZbUHoRiRWiNPUjtoVZRSlEEDfMlsKfeRHwICakwCdSay+Y0jZhTt2FztVrjurad/8Ptfxnb3d2W3KL4fp7c7jm/e3+/A/d3d3SKCCEUAACAAMR/+gIAAOCfhR4DAABCQY8BAAChoMcAAIBQ0GMAAEAo6DEAACAU9BgAABAKegwAAAjld/eY+fl5hUKxlgFrOd1agodCoc7OzqzDPn36pNPplEqlSCQSiUTl5eUXLlxYXV39tZMCAPzVfnePqaysDAQCaxkg6Nl5fPny5ebNm1mHGY3GaDTqcDhomqZp+sWLF06ns6ur69dOCgDwVxP92/9LZn5+fufOnd++ffs9oX78+CGTybxer0ajYd8cHR01Go1v375d+zUAAPxdsn+OGR8f37t3r0Kh2Lx589GjR6enpymKWl1dPXXqlEKhqKysvHLlSjwep/7fiers7NRoNOXl5Q8fPjx+/PiNGzfYUPX19Xfv3k3erYrH45cuXdq0aVNxcbFOp1tZWUnZzvr+/fuZM2c0Gs2WLVuuXr3KnGh8fLy+vr6oqEij0eh0uqWlpUzRUnJJDs6Twp07d6qrq5VK5cmTJ0OhEEVRoVCoqqoqHA6LRKJHjx5lmu73+wsLC5kGMzo6um3bNqVS+eTJk8XFRc765JsL51rwBOGpM095+SdyZgEAwCl7jzl06FBra6vH4xkZGWloaJBKpRRFXbt2LRKJTE5ODg4ODg8P9/T0MIPD4fDMzIzT6ezt7W1oaNDr9f39/cwhn8/ncDgOHDiQHPzWrVtDQ0NDQ0Ozs7MVFRUulyvl7OfPn/d6vXa7fXBwcGBgoLu7m6Iou91uNBr9fr/T6dRqtW1tbTlGS8aTwuTk5KtXr8bGxjwej8VioShqw4YNMzMzcrmcpmmDwZBpeiKREIt/lrStrU2v18/Oztrt9kQiwVmffHPhXAueIFnrzFnerBPTswAA4EZ4BYNBiURC03TK+2q1OhwOMz87HI7du3cTQtxuN0VRwWCQHRaJRNavX+/xeAgh3d3dhw8fdrvdcrmcHVBaWmq325MjJw+IxWJyufzjx4/My4GBgbq6upQr+fDhQ1lZWS7RUl7ypPD161fm/ZGRka1bt3KGyjSdGROJRMRicSAQIIQ8e/aspKSEsz555ZJpLXiCsNKjkdzKy1lS/iwAAFgS/g6kVCqPHTtWV1e3f//+ioqK2traffv2ff78ORAIVFVVMWMSiYRE8jOOXC5XKpXs9KKioqampv7+/vb29r6+vtbW1uTgoVAoGAzW1NRkOvvy8nI0Gq2urmZe7tixg7nBTUxMdHR0uFyuaDSaSCSYTwlZoyXjT4HdT9NqtcFgMK/pjGAwWFhYuHHjRiYI+35KffLKhXMteIKwMlUmU3mzTkzPAgCAU5YeQ1HU48eP37x543Q6vV6v2Wzes2ePxWIRi8WvX79mb6zsBlE6vV5vs9kMBsPY2FhfX1/6LbugoCDfi25ubj59+nRPT49UKl1cXGxsbMw3Gk3TuafwC9OTN81S7vhrySV9Le7fv88fhCdajn55IgBAlr2yFA6HQ6vVEkLkcnn63kvKbhKDpmmVSnXv3r0jR46kjyktLXU4HJmCcG7mLC8vSySS5EtidqKyRkt5mUsKbrebDZ5yiHO6x+ORyWSEkHA4LBaLmQ2lp0+fsntlKfXJK5cU7FrwBGFxRstxr4y/pAAAPLI8vE9PTx88ePD58+crKysLCws2m23Xrl0URRkMhnPnzk1NTfl8vtu3b1+/fj1ThHXr1jU2Nl6+fLmlpSX9qMlkMhqN7969W1paam9vf/nyZfLRgoKClpYWk8m0sLAwNTVltVpPnDih0WhUKtWDBw9CodDc3JzVauWJplKpaJp+//59+l9M5Z4CQ61W0zQ9NzfHM12tVkej0YmJieLi4oaGhq6uLp/PZ7PZMsXMK5dMa5EpSPIXPznrzFneXCYCAOSKvwVFo1Gr1bp9+/bCwsLS0lKDweD3+wkhNE2bTCatViuTyZqamphn4UxPuP39/XK5PBKJpI+JxWIdHR1qtVoqlTY3NwcCgZQB4XDYaDSq1WqtVmu1WmOxGCFkeHi4trZWKpWWlZWZzWb2sT09GiHk4sWLMpmst7c35ey5pJD8OYYQYrVa2VCc0wkhZrP57NmzhBCXy1VTU1NSUmKxWDJ9jskrl0xrwRkka50zlTffBQIA4PGPfwfzj4jH4/gdBgAA9c9/zx8AAP4g/N9lAAAQCnoMAAAIBT0GAACEgh4DAABCQY8BAAChoMcAAIBQ0GMAAEAo6DEAACAU9BgAABAKegwAAAgFPQYAAISCHgMAAEJBjwEAAKH8B1csCKLEBExMAAAAAElFTkSuQmCC)

Mirror: Click here to view the mirror

Coordinated Disclosure Timeline

Vulnerability Reported: 19 May, 2020 14:50 GMT
Vulnerability Verified: 20 May, 2020 14:14 GMT
Website Operator Notified: 20 May, 2020 14:14 GMT
a. Using the ISO 29147 guidelines
β€” β€”
b. Using publicly available security contacts
c. Using Open Bug Bounty notification framework
d. Using security contacts provided by the researcher
Public Report Published
[without any technical details]: 20 May, 2020 14:14 GMT