How an IDOR Vulnerability Led to User Profile Modification
ID: c4353973-2dcc-5b7e-b705-2bf5ae4eabec
STIX ID: report--c4353973-2dcc-5b7e-b705-2bf5ae4eabec
Feed Name: HackerOne Blog
This report describes an IDOR (Insecure Direct Object Reference) vulnerability discovered on mtnmobad.mtnbusiness.com.ng that allowed an authenticated attacker to enumerate account identifiers and update arbitrary account details (including mobile numbers and emails) by modifying the payload sent to the /app/updateUser endpoint; the finding was rated Critical and the report includes reproduction steps, server responses, and recommended mitigations (authorization checks, non-guessable resource identifiers, and rate limiting).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
