IDOR delete any Tickets on ads.tiktok.com
High
T
TikTok
Submitted None
Team Summary
Official summary from TikTok
An IDOR (Insecure Direct Object Reference) vulnerability was found on TikTok ads, through the "draft_order_id" parameter which could have allowed an attacker to delete the support tickets of other users. We thank @datph4m for reporting this to our team and confirming its resolution.
Actions:
Reported by
datph4m
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)