Who:Cybersecurity firm Salt Labs, researchers, and an undisclosed online travel service integrated with commercial airlines.
What:A vulnerability in the OAuth authentication process exposed millions of users to account hijacking. Attackers could exploit the flaw to access users' accounts, impersonate them, and perform actions like booking hotels or car rentals with the victim’s airline loyalty points.
How:The flaw was triggered by a specially crafted link that, when clicked, redirected the user to a manipulated authentication response. This allowed attackers to steal session tokens and hijack accounts. The attack was difficult to detect as it involved manipulating a URL parameter rather than the domain itself. The vulnerability affected services allowing hotel bookings to be added to airline itineraries.
Read the full article HERE