4
3 Comments

Booking website allowed him to enter someone else's account and cancel their reservation: Zero Day Vulnerability

Booking.com Zero-Day Vulnerability - One of my friends got a mail from Booking.com for confirmation of a booking that he didn't make. He checked the email and the link took him to the confirmation page on booking.com. And he canceled the booking only to realize later that Booking.com let him enter someone else's account with all the confidential details required in the email.

Booking.com allowed me to enter someone else's account and cancel their reservation - Zero-Day Vulnerability

https://www.skillsire.com/read-blog/369_booking-com-allowed-me-to-enter-someone-else-039-s-account-and-cancel-their-rese.html

on September 8, 2020
  1. 3

    This does not seem to be a vulnerability..

    Rather someone created a booking.com account with your email and made a booking, which you were able to cancel

  2. 1

    This is not a vulnerability, it's the same as the "Slack magic email" where a secret time-limited token is able to sign you in. A lot of websites use the same way to make secret URLs to your account page that you can only access if you'd guess the very long token.

    If someone uses your email to sign up for something then of course you'll have access to that. You could also just click "reset password" on Booking.com and as your email is linked there reset the password to whatever you want.

  3. 0

    Wow. Thanks for the share. Amazing that such a large company can have such a major vulnerability. Surely this has happened many times before?