how a single JSON parameter allowed unauthorized manipulation(IDOR)

medium.com · Georgezakary · 10 days ago · research
quality 7/10 · good
0 net

It started with a single parameter I wasn’t supposed to control…