🌐 1000$ IDOR : Unauthorized Project Inclusion in Expense
🔗 https://medium.com/@a13h1/1000-idor-unauthorized-project-inclusion-in-expense-b9ce08b28c71
☄️ Quick view:
#bughunting #webattacks #webpentesting
🔗 https://medium.com/@a13h1/1000-idor-unauthorized-project-inclusion-in-expense-b9ce08b28c71
☄️ Quick view:
Hi Everyone! Today, I’m excited to talk about a critical vulnerability I discovered in a platform (let’s call it ExamFit), which allowed users to bypass project status restrictions and submit unauthorized expense reports. Join me as we explore how this flaw was identified and its implications.
#bughunting #webattacks #webpentesting