Loading HuntDB...

Information Disclosure and Privilege Escalation in app.goodhire.com/member/developers/api-settings

High
I
Inflection
Submitted None

Team Summary

Official summary from Inflection

Researcher reported a missing authorization check when purchasing a report. As a result, any valid user with ordering privileges could place an order on behalf of any other account (although would not be able to receive the results of the order). We added an authorization check to ensure that users can only place orders for their own account.

Reported by hackedbrain

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure