Loading HuntDB...

IDOR leads to leak analytics of any restaurant

Medium
U
Uber
Submitted None

Team Summary

Official summary from Uber

The GraphQL service at https://restaurant.uber.com, did not properly perform an authZ check, allowing an attacker to obtain detailed sales statistics, etc for any restaurant.

Reported by 0xprial

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)