ninacoder-info / music-engine-web-wiki

11 stars 6 forks source link

Broken Access Control : IDOR #33

Open Nvz0x opened 1 year ago

Nvz0x commented 1 year ago

The application allows unauthorized access to data of other objects.

A valid user can interact with other user's information as the application is not checking the authorization of the use

PoC:

https://example.com/{USERNAME}/notifications

A valid user can view other users' notifications

Adamanthus commented 11 months ago

2 months later and no reply, I think I will hold off on purchasing this.