Loading HuntDB...

IDOR in merchant.rbmonkey.com allows deleting eShops of another user

High
R
RBKmoney
Submitted None

Team Summary

Official summary from RBKmoney

Website merchant.rbmonkey.com was exposed to an insecure direct object reference vulnerability (IDOR) which may allow an attacker to deleting shop objects of another user.

Reported by rijalrojan

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted