image dsbw
Responsible Disclosure

IDOR Get any Customer all invoices

Merroun Lahcen — DevSecure Published il y a 6 mois
image de IDOR Get any Customer all invoices

Hi, I'm Merroun Lahcen from DevSecure — we specialize in uncovering hidden vulnerabilities that pose real-world risks to modern web applications.


All vulnerabilities shared in these write-ups are fully redacted — any company names, domains, or sensitive details are replaced with placeholders such as company.com. Each finding was responsibly disclosed through the Intigriti platform and has been verified and resolved by the affected vendor.


Every post represents our commitment to ethical hacking, responsible disclosure, and continuous learning — helping organizations strengthen their defenses while contributing to a safer global cybersecurity ecosystem.

1/ create new company and login 2/ go to services-api.company.com/customers/{UUID}/invoices?invoiced=false 3/ change UUID to any UUID and you wil get all invoices informations about the customer Impact IDOR + information disclosure Platform : Intigriti Timeline : Reported: 09/04/2023 Triaged: 10/04/2023 Accepted & paid: 11/04/2023 Bounty: €250