Back to directory
WRITEUP #4666

Chaining an IDOR with a business-logic error to achieve critical impact

IDORLogic flaw
by@jub0bs(Julien Cretel)
Program
-
Published
May 26, 2020
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://jub0bs.com/posts/2020-05-26-idor/
RELATED WRITEUPS
Logic Flaw: I Can Block You from Accessing Your Own Account
Logic BugLogic flaw
Zomatoooo! IDOR in Saved Payments
IDOR
“Like” Bypass on Customer Reviews — €500 bounty
Logic BugLogic flaw
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL

Built with ❤️ by Shubham Rawat