โ† Back to Dashboard
๐Ÿ“Œ Note: You are currently logged in as user (ID: 2). Try viewing other users' profiles!

View User Profile

View My Profile

Request URL:

/vulnerabilities/idor/

๐ŸŽฏ Vulnerability Info

Type: Insecure Direct Object Reference (IDOR)

Severity: High

๐Ÿ’ก How to Exploit

  • User ID is passed as a URL parameter
  • No authorization check verifies ownership
  • Change the ID to access other users' data

๐Ÿงช Try These IDs

?user_id=1 (admin) ?user_id=2 (user - your account) ?user_id=3 (john) ?user_id=4 (jane) ?user_id=5 (guest)

๐Ÿ“Š User Enumeration

ID Username Role
1 admin admin
2 user user
3 john user
4 jane user
5 guest guest

๐Ÿ”ง Burp Suite Intruder

Use Intruder to enumerate all users:

  1. Send request to Intruder
  2. Mark user_id as payload position
  3. Use Numbers payload (1-100)
  4. Start attack and analyze responses