Summary by c3L0Mu1d3R
A Broken Object Level Authorization (IDOR) vulnerability was identified in the DIRS (FCC) production environment, where an authenticated API endpoint allows low-privileged users to access full user profiles and associated company data of other users by modifying a predictable numeric userid in the request path.
This issue results in the exposure of personally identifiable information (PII) and organizational metadata, enables user enumeration, and increases the risk of targeted phishing and social-engineering attacks, impacting a FCC system used by telecommunications providers.