Critical IDOR - Delete any group of any organization remotely

Disclosed: 2016-06-12 16:06:10 By itly To veris
Unknown
Vulnerability Details
Hello Team, I have found a critical IDOR for deleting any groups of any organization remotely. It means an attacker can easily delete any group of any organization from his account by just chaning the group_id in delete request. This is similar to previously reported IDOR to delete any members. So I am not writing down steps to reproduce again as it is also similar but jut to perform in Groups section. Proof of Concept: Please find the attached screenshots. Do evaluate it and inform me accordingly. Best Regards, Hely H. Shah
Actions
View on HackerOne
Report Stats
  • Report ID: 120121
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report