Back to directory
WRITEUP #6275

How a simple IDOR become a $4K User Impersonation vulnerability

IDOR
by@Shahmeer_Amir(Shahmeer Amir)
Bounty
4,250
Program
-
Published
Jul 8, 2017
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://shahmeeramir.com/how-a-simple-idor-become-a-4k-user-impersonation-vulnerability-705291b55c0d
RELATED WRITEUPS
Zomatoooo! IDOR in Saved Payments
IDOR
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel
IDORBroken Access Control
Bypassing ACLs – IDOR exploitation via HPP
IDORHTTP parameter pollution

Built with ❤️ by Shubham Rawat