Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

YouTube Flaw Allowed Removal of Any Video: Researcher

A researcher has identified a vulnerability in YouTube that could have been exploited by an attacker to delete any video from the Google-owned video sharing website.

A researcher has identified a vulnerability in YouTube that could have been exploited by an attacker to delete any video from the Google-owned video sharing website.

The issue was discovered over the weekend by Russia-based security researcher Kamil Hismatullin. The expert, who has reported several flaws to Google, decided to analyze YouTube Creator Studio after being awarded $1,337 as part of the search giant’s recently introduced Vulnerability Research Grants program.

In a blog post published on Tuesday, Hismatullin explained that he was looking for cross-site scripting (XSS) and cross-site request forgery (CSRF) vulnerabilities when he identified a logical bug that allowed him to remove any video from YouTube with the following POST request:

https://www.youtube.com/live_events_edit_status_ajax?action_delete_live_event=1

The request must include a session token, which is available in the page’s source code, and the ID of the video that is being deleted, a string that can be found in the video’s URL. The researcher has published a proof-of-concept video to demonstrate his findings.

Google addressed the vulnerability just hours after it was reported by Hismatullin. The researcher was awarded $5,000 for his findings, which is the maximum reward for logic flaws that lead to bypassing significant security controls in normal Google applications.

Advertisement. Scroll to continue reading.

Related: Researcher Gets $5000 for XSS Flaw in Google Apps Admin Console

Related: Email Spoofing Flaw Found in Google Admin Console

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Rapid7 announced that Wael Mohamed will assume the role of Chief Executive Officer, replacing current Chief Executive Officer Corey Thomas, who will become Executive Chairman of the Board.

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter.

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.