IDOR in one subdomain of █████████ -> change information of pets without athorization!
Medium
M
Mars
Submitted None
Team Summary
Official summary from Mars
A potential security concern was found on the subdomain at ███████. It seems that any user has the ability to modify pet information belonging to others on this subdomain. Given the nature of the subdomain, which is related to pets, the information being altered could have significant implications. This raises a potential risk regarding the confidentiality and accuracy of pet-related data on the mentioned website.
Actions:
Reported by
haoshokunoo
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)