Attacker can unpin posts from companies he's not part of.
Low
L
LinkedIn
Submitted None
Team Summary
Official summary from LinkedIn
The researcher found an Insecure Direct Object Reference (IDOR) to unpin any company's post on LinkedIn, without having the required permissions.
Actions:
Reported by
spaceboy20
Report Details
Additional information and metadata
State
Closed
Substate
Resolved