Back to directory
WRITEUP #5737

How Misconfigured API leaked user private information?

IDORBroken authorization
byYeasir Arafat
Program
-
Published
Oct 26, 2018
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://medium.com/@Skylinearafat/how-misconfigured-api-leaked-user-private-information-e3e8c13e52e4
RELATED WRITEUPS
CVE-2024-45195: Apache OFBiz Unauthenticated Remote Code Execution (Fixed)
RCEForced browsing
Zomatoooo! IDOR in Saved Payments
IDOR
How 1 Exposed Honeywell API Gave us Control Over an Internal Engineering System
ReconMissing authentication
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL

Built with ❤️ by Shubham Rawat