Loading HuntDB...

Able to Become Admin for Any LINE Official Account

Critical
L
LY Corporation
Submitted None

Team Summary

Official summary from LY Corporation

The reporter found an issue where abusing an IDOR would allow for an attacker to become an administrator of any LINE Official Account. This was due to an issue where the group ID could be extracted and/or easily guessed, combined with lack of authentication, leading to being able to craft a request that resulted in being given administration rights to that LINE Official Account.

Reported by ngalog

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Privilege Escalation