Italian expert Vincenzo C. Aka @Procode701 has discovered a critical Improper Authentication vulnerability affecting the UBER platform that allowed password reset for any account. The Italian expert discovered a serious problem in the password reset process that could be exploited to generate an authentication token inAuthSessionID That could be used to change the password using the standard link that is present in the change password form. The Uber platform was generating a specific session token every time a user was sending password reset email. The impact of the vulnerability is severe, it allowed a hacker to access any account and any user’s data.”]
Source: https://securityaffairs.co/wordpress/59210/hacking/uber-improper-authentication.html

