Loading HuntDB...

████ ' can add animal to other account ' at ██████

Medium
M
Mars
Submitted None

Team Summary

Official summary from Mars

A security vulnerability was identified where an attacker can add a pet to another user's account without authorization. The vulnerability exists due to a lack of proper access controls, allowing the attacker to modify the idUsuario parameter in the request to associate the pet with a different account. This vulnerability falls under the CWE-639 category, "Authorization Bypass Through User-Controlled Key," which describes a system's failure to prevent one user from accessing another user's data by modifying the key value.

Reported by 0xs4m

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)