- [TARGET]
- HackerOne
- [SEVERITY]
- critical
- [CLASS]
- Vuln & CVE
An IDOR that became account takeover through OAuth
The object reference was only half of it. This follows the OAuth binding that trusted a client-supplied identifier, and the full takeover it allowed.