India - An Insecure Direct Object Reference (IDOR) allowed unauthorized access to view card index number and monetary balance
Medium
S
Starbucks
Submitted None
Team Summary
Official summary from Starbucks
mr_intrusionist discovered an Insecure Direct Object Reference (IDOR) which affects the https://card.starbucks.in/StarbucksMSRModule/starbucksGetCardData.do endpoint through the cardId parameter. This allowed an authenticated, but unauthorized user to iterate cards and view the balance. @mr_intrusionist — thank you for reporting this vulnerability and confirming the resolution.
Actions:
Reported by
mr_intrusionist
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)