IDOR allows information disclosure
High
S
Semrush
Submitted None
Team Summary
Official summary from Semrush
Adam discovered a vulnerability related to information disclosure within the Social Media Inbox tool. This tool is designed to enable users to link their social media accounts, oversee content, and engage with their audience. It includes a task tracker feature, which allows users to delegate message management to their colleagues on Semrush. However, it was found that user can assign a message to any userid. The subsequent internal review revealed no evidence of this vulnerability being exploited by unauthorized parties.
Actions:
Reported by
a_d_a_m
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)