←PR REVIEWInsecure Direct Object Reference (IDOR)#389AirbnbDropbox
⏱ 00:00Junior~12 min
PULL REQUEST
Open#389 · 1 commit
Insecure Direct Object Reference (IDOR)
junior-dev-99 wants to mergefeature/invoice-download→main
JU
junior-dev-99
1 file changed · 6 days ago
YOUR MISSION
A security researcher privately reported they can download any user's invoice by changing a number in the URL. A junior dev wrote this endpoint last sprint. It passed code review — but the bug is sitting in plain sight.