vulns.co
/
GKData.io MCP

Back to Playbooks

SCIM, directory sync, and invites

Provisioning bugs are authorization bugs on user creation. Compare two orgs you belong to. Do not create users in a tenant that is not yours.

Tags: scim, invite, provision

Level: intermediate

Method

  1. List the routes you were given

    Invite create, invite accept, SCIM Users, and directory sync. Stay on the routes the program includes. A discovered admin path is inventory until you are allowed to call it.

    Tools: Burp Suite

  2. Two orgs you belong to

    Use a member in org A and a member in org B. Replay A's create or role change with B's token. The question is whether the org id is checked on the write.

    Tools: Burp Suite

  3. Role on the token you have

    Call the same route as a member and as an admin, if the program gave you both. A member token that changes a role is the note. Do not guess an admin id.

    Tools: Burp Suite

  4. Invite token

    Accept an invite you issued, in a browser other than the one that created it, and then a second time. Record whether it is bound to an email and whether it is single-use. The mailbox has to be yours.

    Tools: browser

  5. Directory sync drift

    If a user is removed in the directory and still has a session in the app, record the delay you observed. Do not delete someone else's account to test it.

    Tools: browser

Field notes

  • SCIM and the invite form can authorize differently. Test the one you can reach.
  • An invite URL token that is reusable belongs in the same note as the reset brief. Say which behavior you showed.
  • Creating a user in a third org is out.

References