idor

Base Steps:

  1. Account Setup: Create two accounts or enumerate users first.

  2. Endpoint Check: Determine if the endpoint is private or public and if it contains any ID parameter.

  3. Parameter Manipulation: Change the parameter value to another user's ID and observe any changes to their account.

  4. Done!

Additional Tests:

Last updated