████ ' can add animal to other account ' at ██████
Medium
M
Mars
Submitted None
Team Summary
Official summary from Mars
A security vulnerability was identified where an attacker can add a pet to another user's account without authorization. The vulnerability exists due to a lack of proper access controls, allowing the attacker to modify the idUsuario parameter in the request to associate the pet with a different account. This vulnerability falls under the CWE-639 category, "Authorization Bypass Through User-Controlled Key," which describes a system's failure to prevent one user from accessing another user's data by modifying the key value.
Actions:
Reported by
0xs4m
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)