IDOR - Leaking of team data (name, email, ID, member ID) via POST /api/v1/graphql `FetchMemberships` operation
Medium
T
Tools for Humanity
Submitted None
Team Summary
Official summary from Tools for Humanity
An authorization bypass issue was identified and subsequently remediated in the `FetchMemberships` GraphQL operation. This issue had allowed individuals no longer associated with the organization to access sensitive team member data due to inadequate validation of user permissions. The information that was potentially accessible included names, email addresses, roles, and IDs of current team members.
Actions:
Reported by
aghayeone-blocked
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.00
Submitted
Weakness
Insecure Direct Object Reference (IDOR)