Loading HuntDB...

Exploitable live argument in onClick Function leads to Data Leakage of Inactive/Suspended Products

Medium
T
TikTok
Submitted None

Team Summary

Official summary from TikTok

Within the "Search Product" function in TikTok Shop Seller API, the ability to access inactive or suspended products could have been achieved by tampering with the "live" parameter in the API request. We thank @696e746c6f6c for reporting this to our team and confirming its remediation.

Reported by 696e746c6f6c

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$1000.00

Submitted

Weakness

Business Logic Errors