A security researcher explains the technical details of finding IDOR vulnerabilities in a bug bounty program. The researcher discovered two IDOR flaws, one allowing deletion of the CMS of all customers and another allowing deletion of all users' personal data. The vulnerabilities were categorized as P3 and P1 respectively.

4m read timeFrom infosecwriteups.com
Post cover image
Table of contents
IDOR “ Insecure direct object references” , my first P1 in BugbountyIDOR ? Ok but what is it finally ?Write UPSo the bugbounty plateform accepted the vulnerability as P3FROM P3 TO P1The bugbounty plateform accepted the vulnerability as P1 this time

Sort: