Major Security Hole at Tumblr

Mark Hendrickson

Mark Hendrickson is a product designer in San Francisco, California. He has been the product lead at Lift, the CEO and co-founder of the consumer internet company Worldly Developments and, prior to that, a writer and web designer for TechCrunch. → Learn More

Tuesday, April 15th, 2008

It’s not a good day for tumbleblogging. Someone over at Hacker News just noticed that users can access an admin panel for the site by entering a simple admin URL after signing in.

Among the capabilities exposed is the ability to search for users and reset their passwords. You can also change their email addresses, view their activity logs, and change other miscellaneous settings like daily limits on post types.

According to the person who posted the exploit on Hacker News, Tumblr has already been notified of the security hole but apparently has yet to fix it. Update: They’ve just fixed it. It was a known exploit for about an hour. Update 2: Tumblr’s security notice.

Tags:
blog comments powered by Disqus