Loading HuntDB...

Change the rating of any trip, therefore change the average driver rating

Medium
U
Uber
Submitted None

Team Summary

Official summary from Uber

The endpoint used for rating the driver did not validate correctly if the trip corresponded to one made per user logged in, therefore knowing the tripUUID, driverUUID and userId made it possible to change the rating of any trip. Attack scenario: a bad driver with poor ratings and programming skills could change the ratings of their past trips to artificially inflate their rating. Thanks again, @overjt!

Reported by overjt

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$1500.00

Submitted

Weakness

Business Logic Errors