logo

How an IDOR Vulnerability Led to User Profile Modification

ID: c4353973-2dcc-5b7e-b705-2bf5ae4eabec

STIX ID: report--c4353973-2dcc-5b7e-b705-2bf5ae4eabec

Feed Name: HackerOne Blog

Threat Score
70/100

Date Published: 2024-11-27

Date Updated: 2026-06-12

...
...

This report describes an IDOR (Insecure Direct Object Reference) vulnerability discovered on mtnmobad.mtnbusiness.com.ng that allowed an authenticated attacker to enumerate account identifiers and update arbitrary account details (including mobile numbers and emails) by modifying the payload sent to the /app/updateUser endpoint; the finding was rated Critical and the report includes reproduction steps, server responses, and recommended mitigations (authorization checks, non-guessable resource identifiers, and rate limiting).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.