███████ ' can delete any animal from other account ' at ██████████
Medium
Vulnerability Details
hi team
i found ███████████ , i can delete any animal from other account easily
1. Go to registration page (████████)
2. Verified your account.
3. Go to login page and login your account.
For the fastly test, use this credentials to login (my test account)
█████████████████ For Attacker
email: ████████████████
pass: Password
█████████████ For Victim
email: ████
pass: Password
After login i create 2 account for attacker and victim , in the attacker's account, i delete my animal, and i send request to burp .. i change my animal id to victim animal id so i succeeded
███
## Impact
████████████████
Actions
View on HackerOneReport Stats
- Report ID: 1947376
- State: Closed
- Substate: resolved
- Upvotes: 16