View & add to cart unlisted items via IDOR
High
I
Instacart
Submitted None
Team Summary
Official summary from Instacart
Access Control vulnerability that would let an attacker order certain items from the API, even though they are missing from the Web catalog
Actions:
Reported by
bigshaq
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)