Loading HuntDB...

View & add to cart unlisted items via IDOR

High
I
Instacart
Submitted None

Team Summary

Official summary from Instacart

Access Control vulnerability that would let an attacker order certain items from the API, even though they are missing from the Web catalog

Reported by bigshaq

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)