Able to Become Admin for Any LINE Official Account
Critical
L
LY Corporation
Submitted None
Team Summary
Official summary from LY Corporation
The reporter found an issue where abusing an IDOR would allow for an attacker to become an administrator of any LINE Official Account. This was due to an issue where the group ID could be extracted and/or easily guessed, combined with lack of authentication, leading to being able to craft a request that resulted in being given administration rights to that LINE Official Account.
Actions:
Reported by
ngalog
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Privilege Escalation