Critical IDOR - Delete any group of any organization remotely
Unknown
Vulnerability Details
Hello Team,
I have found a critical IDOR for deleting any groups of any organization remotely. It means an attacker can easily delete any group of any organization from his account by just chaning the group_id in delete request.
This is similar to previously reported IDOR to delete any members. So I am not writing down steps to reproduce again as it is also similar but jut to perform in Groups section.
Proof of Concept: Please find the attached screenshots.
Do evaluate it and inform me accordingly.
Best Regards,
Hely H. Shah
Actions
View on HackerOneReport Stats
- Report ID: 120121
- State: Closed
- Substate: resolved
- Upvotes: 3