Loading HuntDB...

read and message other user's messages

Critical
R
Reddit
Submitted None
Reported by beksem35

Vulnerability Details

Technical details and impact analysis

Insecure Direct Object Reference (IDOR)
go to your account's chat page, stop the request and change the reddit session parameter, now leave the request and you will be able to access the test account's chat screen send the request to the repeater change the reddit session parameter and send it then you will see the return result is 200 show reply in browser and copy and paste the address into your browser you will access the chat page of your test account ## Impact other users' chat screen can be accessed and message can be sent

Report Details

Additional information and metadata

State

Closed

Substate

Not-Applicable

Submitted

Weakness

Insecure Direct Object Reference (IDOR)