Bitwarden: A Low-Privilege Member Could Take Over Another Member's Vault (POST /auth-requests/admin-request)
HIGH> The server looked up the victim by the email in my request body — then never checked that email was mine. The latest writeup in my Bitwarden series, and my favorite of the set:...