Loading HuntDB...

Privilege Escalation - A Low Privilege User who does not have access to the user management module can remove the owner of the business account

Low
Y
Yelp
Submitted None

Team Summary

Official summary from Yelp

An unauthorised business user can remove the owner of the business account.

Reported by vijaysimha-reddy

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic