read and message other user's messages
Critical
R
Reddit
Submitted None
Actions:
Reported by
beksem35
Vulnerability Details
Technical details and impact analysis
go to your account's chat page, stop the request and change the reddit session parameter, now leave the request and you will be able to access the test account's chat screen
send the request to the repeater change the reddit session parameter and send it then you will see the return result is 200
show reply in browser and copy and paste the address into your browser you will access the chat page of your test account
## Impact
other users' chat screen can be accessed
and message can be sent
Report Details
Additional information and metadata
State
Closed
Substate
Not-Applicable
Submitted
Weakness
Insecure Direct Object Reference (IDOR)