Loading HuntDB...

IDOR in one subdomain of █████████ -> change information of pets without athorization!

Medium
M
Mars
Submitted None

Team Summary

Official summary from Mars

A potential security concern was found on the subdomain at ███████. It seems that any user has the ability to modify pet information belonging to others on this subdomain. Given the nature of the subdomain, which is related to pets, the information being altered could have significant implications. This raises a potential risk regarding the confidentiality and accuracy of pet-related data on the mentioned website.

Reported by haoshokunoo

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)