IDOR in merchant.rbmonkey.com allows deleting eShops of another user
High
R
RBKmoney
Submitted None
Team Summary
Official summary from RBKmoney
Website merchant.rbmonkey.com was exposed to an insecure direct object reference vulnerability (IDOR) which may allow an attacker to deleting shop objects of another user.
Actions:
Reported by
rijalrojan
Report Details
Additional information and metadata
State
Closed
Substate
Resolved