Loading HuntDB...

IDOR on in-app hardcoded zombie endpoint

Medium
B
Bykea
Submitted None

Team Summary

Official summary from Bykea

@bugbountywithmarco **discovered an Insecure Direct Object Reference (IDOR) vulnerability in a hardcoded legacy (zombie) endpoint that was no longer actively used but remained accessible.** By reverse engineering the Android app and reviewing the code for unused endpoints, the researcher identified an exposed API that leaked sensitive details related to drivers involved in other users’ trips, without validating trip ownership.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)