Delete any post for all users via IDOR in usememos/memos
Valid
Reported on
Dec 24th 2022
Description
Delete any post for all users via IDOR
Proof of Concept
1- Post anything
2- Open Burp Suite to intercept the request
3- When deleting the post, we will notice that there is DELETE /api/memo/1010 in the request, Here the post id will be 1010
4- This number can be changed and any post you want will be deleted
More explanation in a video
https://drive.google.com/file/d/1uaRsJmVkmpHM0YXm3WirXNWQKXkkRCcK/view
Impact
The attacker can delete users' posts
We are processing your report and will contact the
usememos/memos
team within 24 hours.
16 days ago
samirwaleed modified the report
16 days ago
We have contacted a member of the
usememos/memos
team and are waiting to hear back
15 days ago
samirwaleed modified the report
13 days ago
The researcher's credibility has increased: +7
to join this conversation