Loading HuntDB...

Use of unreleased features in programming education service (https://entry.line.me)

Medium
L
LY Corporation
Submitted None

Team Summary

Official summary from LY Corporation

LINE entry is a service that provides programming education for children (https://entry.line.me). Sharing creations was a feature that was previously only available to admins, and the feature was still under development before creators (users) were allowed to use it. The vulnerability was a case in which creators (users) were able to share creations without permission by forcing a feature that had not been updated.

Reported by tosun

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Business Logic Errors