[IODR] Get business trip via organization id
Unknown
Vulnerability Details
Hi Uber,
I found issue on https://business.uber.com/server/organizations/[id]/trips2?per_page=15&requestAtStart=&requestAtStop=&count=true
Step to reproduce:
1. Get https://business.uber.com/server/organizations/[your_organization_id]/trips2?per_page=15&requestAtStart=&requestAtStop=&count=true
2. Chang to victim organization If valid id, it will return result, but if not it will show error with internal state
```
{"error":{"name":"TchannelUnexpectedError","fullType":"tchannel.unexpected","type":"tchannel.unexpected","message":"Unexpected Error: 'validation_error.must_be_a_valid_uuid_v4'","isErrorFrame":true,"codeName":"UnexpectedError","errorCode":5,"originalId":2,"remoteAddr":"10.160.14.41:21306"}}
```
In `employee_invites`, it return 403.
As previous I report #151465 , I can get organization id or just enum it ( very difficult).
Best regards,
Severus
Actions
View on HackerOneReport Stats
- Report ID: 151470
- State: Closed
- Substate: resolved
- Upvotes: 8