Insecure Direct Object Reference (IDOR) (CWE-639)CVSS 6.5€470
IDOR leads Unauthorized Staff Member Removal via Insufficient Authorization Checks
Missing authorization checks allow unauthorized users to remove staff members from accounts they do not own, leading to potential disruption and abuse.
Vulnerability Details
Endpoint:
POST /account/dashboard/accounts HTTP/2
Request Payload:
MemberId=76671&RemoveMember=remove