Loading HuntDB...

IDOR allows information disclosure

High
S
Semrush
Submitted None

Team Summary

Official summary from Semrush

Adam discovered a vulnerability related to information disclosure within the Social Media Inbox tool. This tool is designed to enable users to link their social media accounts, oversee content, and engage with their audience. It includes a task tracker feature, which allows users to delegate message management to their colleagues on Semrush. However, it was found that user can assign a message to any userid. The subsequent internal review revealed no evidence of this vulnerability being exploited by unauthorized parties.

Reported by a_d_a_m

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)