IDOR leads to leak analytics of any restaurant
Medium
U
Uber
Submitted None
Team Summary
Official summary from Uber
The GraphQL service at https://restaurant.uber.com, did not properly perform an authZ check, allowing an attacker to obtain detailed sales statistics, etc for any restaurant.
Actions:
Reported by
0xprial
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)