Loading HuntDB...

[www.zomato.com] IDOR - Leaking all Personal Details of all Zomato Users through an endpoint

High
Z
Zomato
Submitted None

Team Summary

Official summary from Zomato

Hacker is able to get the PI(Personal Information) of any Zomato user.

Reported by prateek_0490

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)