Loading HuntDB...

IDOR in activateFuelCard id allows bulk lookup of driver uuids

Low
U
Uber
Submitted None

Team Summary

Official summary from Uber

Due to an IDOR in the `activateFuelCard` endpoint, an attacker could enumerate driver UUIDs. When given a sequential card ID number, the endpoint returned a driver’s UUID given, allowing an attacker to gather many driver UUIDs for use in a different attack. Thanks, @cablej!

Reported by cablej

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)