Loading HuntDB...

IDOR to account takeover on POST to █████████ by changing member_id parameter

Critical
M
Mars
Submitted None

Team Summary

Official summary from Mars

The website endpoint "██████" is exposed to multiple identifier vulnerabilities, which could potentially result in a complete takeover of user accounts. If exploited, malicious actors could gain full control over the victim's account, posing a significant security risk.

Reported by xandsz

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)