unrestricted-deletion

1 article
sort: new top best
clear filter
0 7/10

Ribose had an IDOR vulnerability allowing attackers to delete or modify other users' profile photos by simply changing the user ID in DELETE/POST requests while reusing their own valid CSRF token and session, effectively bypassing authorization checks.

Ribose
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details