http-method-testing

1 article
sort: new top best
clear filter
0 5/10

An IDOR vulnerability in an e-commerce application's address management API allowed exposure of other users' sensitive information (names, addresses, phone numbers) through a POST request to set default address endpoint that returned 200 with empty body but still processed sequential address IDs. The vulnerability was discovered when the payment page displayed a different user's address data.

Rahul Varale
rahulvarale.medium.com · kh4sh3i/bug-bounty-writeups · 17 hours ago · details