Ajay Magar
Oct 17, 2022

--

app send email verification token as userID. so i search others usersID in diff api responses. in /users/ api i got all users userID so with that infomation i took over account now tell me where it's incomplete.

--

--

Ajay Magar
Ajay Magar

Written by Ajay Magar

Application Security, Bug Bounty

Responses (1)