Change the rating of any trip, therefore change the average driver rating
Medium
U
Uber
Submitted None
Team Summary
Official summary from Uber
The endpoint used for rating the driver did not validate correctly if the trip corresponded to one made per user logged in, therefore knowing the tripUUID, driverUUID and userId made it possible to change the rating of any trip. Attack scenario: a bad driver with poor ratings and programming skills could change the ratings of their past trips to artificially inflate their rating. Thanks again, @overjt!
Actions:
Reported by
overjt
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$1500.00
Submitted
Weakness
Business Logic Errors