02-01-2021 10:34 AM
When I send an invitation thru the Ruckus Unleashed App (Android), the links the App sends starts like this:
http://unleasheddev.com/bmM9dW40MjE4MDIwMDU5[redacted]
It looks to me like the invitations created points to a site no longer under Ruckus control.
Have you been hacked or just allowed a domain to expire, letting someone else take over?
That site could register all clicks on links in invitations, including the GUID that should be a secret!
Looks to me like a MAJOR security issue. Will you look into it?
02-01-2021 10:35 AM
02-01-2021 03:39 PM
Hi Robert. We are aware of this issue and fixing it.
02-02-2021 08:54 AM
Thank you for the update.
Should we worry about the invitations we have already sent?
If the unleasheddev.com domain is not under your control, every request could have been logged.
02-02-2021 05:52 PM
Hi Robert, the invites by themselves do not expose any information. The app knows how to get the required information from it.
By the way with this invite on Android you will see a prompt to either open it on the browser or the Unleashed mobile app. When the user selects Mobile App, the Mobile App opens and gets access to this link. In this case this link is not hit at all.