Back to directory
WRITEUP #4550

[Writeup][Bug Bounty][Tokopedia] Manipulate Other User’s Cart and Wishlist on Tokopedia [EN]

IDOR
by@fadhilthomas(Muhammad Thomas Fadhila Yahya)
Bounty
135
Program
Tokopedia
Published
Jul 3, 2020
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://fadhilthomas.github.io/post/bug-bounty-tokopedia-03/
RELATED WRITEUPS
Zomatoooo! IDOR in Saved Payments
IDOR
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel
IDORBroken Access Control
Bypassing ACLs – IDOR exploitation via HPP
IDORHTTP parameter pollution

Built with ❤️ by Shubham Rawat