Privilege Escalation on TikTok for Business
Medium
T
TikTok
Submitted None
Team Summary
Official summary from TikTok
An IDOR (Insecure Direct Object Reference) vulnerability was found on the "org_id" and "account_id" parameters on a Business.TikTok.com endpoint, which could have resulted in an authenticated user with "Analyst" level permissions to close another user's ads accounts. We thank @naaash for reporting this to our team.
Actions:
Reported by
naaash
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)