Loading HuntDB...

█████████ when adding branches to your account

Critical
M
Mars
Submitted None

Team Summary

Official summary from Mars

A vulnerability has been identified in the branch addition functionality of the Royal Canin specialized channel website ██████████. The issue is classified as an Insecure Direct Object Reference (IDOR) vulnerability, which allows unauthorized users to add branches to any account by manipulating the customer's routing number (RUT) in the request parameter.

Reported by kh4rish34v3n

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)