Glastonbury ticket hijack vulnerability fixed
ID: 34b0979d-4154-5c78-9899-d8bea2915ded
STIX ID: report--34b0979d-4154-5c78-9899-d8bea2915ded
Feed Name: Pen Test Partners Blog
This report details a session management vulnerability on glastonbury.seetickets.com where the session token issued via the contact-us login could be reused to access the registration edit page, allowing attackers with publicly sourced registrationNumber:postcode pairs to change ticket delivery addresses and view PII. The attack is demonstrated with cURL requests and cookie reuse of the IkTmgflrEi72NixCIcjzA value; SeeTickets responded promptly and fixed the flaw, underscoring the importance of responsible disclosure and caution against sharing registration details publicly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
