Get all file in resource of any user and Delete any file of any user via IDOR in usememos/memos
Valid
Reported on
Dec 26th 2022
Description
Easily GET information of all files uploaded by all users in Resources via API https://demo.usememos.com/api/resource/$id_resource (method GET) Easily DELETE of all files uploaded by all users in Resources via API https://demo.usememos.com/api/resource/$id_resource (method DELETE)
Proof of Concept
PoC link: https://drive.google.com/file/d/117gzDOyAE890kLgDYe46hOeRcdyjZX38/view?usp=sharing
Impact
The vulnerability affects all files of all users on the system
We are processing your report and will contact the
usememos/memos
team within 24 hours.
14 days ago
We have contacted a member of the
usememos/memos
team and are waiting to hear back
13 days ago
The researcher's credibility has increased: +7
to join this conversation