HackerOne disclosed on HackerOne: Account takeover of existing...

After numerous attempts and understanding, I was able to take over existing user accounts through SCIM provisioning. When using SCIM provisioning, the following must be met: * Verified domain. * Working SSO configuration. Initially, I thought this would automatically be a certain loophole. In my …