IDOR to account takeover on POST to █████████ by changing member_id parameter
Critical
M
Mars
Submitted None
Team Summary
Official summary from Mars
The website endpoint "██████" is exposed to multiple identifier vulnerabilities, which could potentially result in a complete takeover of user accounts. If exploited, malicious actors could gain full control over the victim's account, posing a significant security risk.
Actions:
Reported by
xandsz
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)