Critical IDOR - Delete any terminal/gatekeeper of any organization remotely

Disclosed: 2016-06-12 16:05:49 By itly To veris
Unknown
Vulnerability Details
Hello Team, I have found a critical IDOR issue due to which an attacker can easily detele any terminal/gatekeeper of any organization by just changing the ID. Proof of Concept: Please find the attached screenshots. Best Regards, Hely H. Shah
Actions
View on HackerOne
Report Stats
  • Report ID: 120288
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report