IDOR on in-app hardcoded zombie endpoint
Medium
B
Bykea
Submitted None
Team Summary
Official summary from Bykea
@bugbountywithmarco **discovered an Insecure Direct Object Reference (IDOR) vulnerability in a hardcoded legacy (zombie) endpoint that was no longer actively used but remained accessible.** By reverse engineering the Android app and reviewing the code for unused endpoints, the researcher identified an exposed API that leaked sensitive details related to drivers involved in other users’ trips, without validating trip ownership.
Actions:
Reported by
bugbountywithmarco
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)