Cross-user authentication bug (possibly serious)

Joined
Mar 18, 2019
Messages
1
Hi,

This is probably a serious bug, I just got served the front page of a different MangaDex user.

I didn't do anything special, just opened my browser and clicked the MangaDex bookmark. I didn't notice that the login user was wrong at first, instead I noticed that the chapters from latest updates were not filtered to my languages, then I clicked on Follows and saw that none of those manga were manga that I was following, only then I noticed the wrong user name at the top-right corner of the page.

I opened another tab and accessed MangaDex again on that new tab, which now shows my correct username and the correct manga I follow, which is the tab I'm sending this message from now. This is desktop Firefox, and I believe I haven't accessed MangaDex in this browser since before the server transition (I use mobile most of the time), so it is likely that my login cookies were from before the transition (they may have been refreshed, since now I'm back to my correct login). I still have the original tab logged with the wrong user open, and I can provide a screenshot or inspect the DOM/JS of the page if necessary (I won't post here for the privacy of the other user, contact me privately if possible).

Thanks.
 

rdn

Forum Admin
Staff
Developer
Joined
Jan 18, 2018
Messages
281
@halfbit sounds like a caching issue from our ddos provider. Hopefully it was just a hiccup and nothing systematic, havent seen any other reports so far.

If you experience it again, let us know.
 
Dex-chan lover
Joined
Jan 18, 2018
Messages
714
That's a little frightening.
What manga someone reads isn't normally a huge deal, though any privacy violation is bad and an issue like this is very much so. Mind you, MD hosting hentai does mean that for those of us subject to tyrannical laws regarding "fictional persons", that list could be damaging if someone malicious got ahold of it.
But what's particularly concerning to me is the persistent sessions list. That page lists your browser, OS, and even the towns you logged in from, as well as the date and time that you logged in. Or rather, towns plural, meaning it's your movements being leaked, not just instantaneous location.
 

Users who are viewing this thread

Top