Loading HuntDB...

IDOR delete any Tickets on ads.tiktok.com

High
T
TikTok
Submitted None

Team Summary

Official summary from TikTok

An IDOR (Insecure Direct Object Reference) vulnerability was found on TikTok ads, through the "draft_order_id" parameter which could have allowed an attacker to delete the support tickets of other users. We thank @datph4m for reporting this to our team and confirming its resolution.

Reported by datph4m

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)