Privilege Escalation - A Low Privilege User who does not have access to the user management module can remove the owner of the business account
Low
Y
Yelp
Submitted None
Team Summary
Official summary from Yelp
An unauthorised business user can remove the owner of the business account.
Actions:
Reported by
vijaysimha-reddy
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic