Unauthenticated Access to Internal Files via Direct Object Reference (UUID-based) Leading to Sensitive Data Exposure

Disclosed by
Maholi_Tumanggor
Summary by Maholi_Tumanggor

An unauthenticated access control vulnerability allowed access to internal files by directly referencing UUID-based resources. The issue could potentially expose sensitive information to unauthorized users. The vulnerability was responsibly reported to the organization for remediation.

Activity