HackerOne Disclosed Reports - 2026-10-01

0 Replies, 10 Views

Logo
Critical
resolved

IDOR allows user to access report details via reference.json endpoint


Bug reported by sm41ldrag0n_mbbank was disclosed at October 1, 2026, 1:27 am   |   Insecure Direct Object Reference (IDOR)

An information disclosure vulnerability was identified in a report details endpoint that allowed unauthorized users to access private report information. Despite the endpoint returning an access-denied error response, sensitive report details were inadvertently exposed in the error message body. The vulnerability was discovered through testing with standard user accounts and has since been fixed. No evidence of exploitation was found.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)