Get organization info base on uuid
U
Uber
Submitted None
Actions:
Reported by
severus
Vulnerability Details
Technical details and impact analysis
Hi Uber,
I found issue on https://business.uber.com/server/employees
Step to reproduce:
1. Send post request to https://business.uber.com/server/employees:
2. Change `userUuid` of other user and then see organization info if they has valid organization and their persinol info
Best ragards,
Severus
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$3000.00
Submitted
Weakness
Improper Authentication - Generic