logo

Glastonbury ticket hijack vulnerability fixed

ID: 34b0979d-4154-5c78-9899-d8bea2915ded

STIX ID: report--34b0979d-4154-5c78-9899-d8bea2915ded

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-06-28

Date Updated: 2026-03-24

Author: Lewis K

...
...

This report details a session management vulnerability on glastonbury.seetickets.com where the session token issued via the contact-us login could be reused to access the registration edit page, allowing attackers with publicly sourced registrationNumber:postcode pairs to change ticket delivery addresses and view PII. The attack is demonstrated with cURL requests and cookie reuse of the IkTmgflrEi72NixCIcjzA value; SeeTickets responded promptly and fixed the flaw, underscoring the importance of responsible disclosure and caution against sharing registration details publicly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.