Site icon API Security Blog

Get all file in resource of any user and Delete any file of any user via IDOR

# Description
Easily GET information of all files uploaded by all users in Resources via API https://demo.usememos.com/api/resource/$id_resource (method GET)
Easily DELETE of all files uploaded by all users in Resources via API https://demo.usememos.com/api/resource/$id_resource (method DELETE)
# Proof of Concept
# PoC link: https://drive.google.com/file/d/117gzDOyAE890kLgDYe46hOeRcdyjZX38/view?usp=sharingRead More

Exit mobile version