[store.line.me] Still can change wishlist URL although wishlist is set to private

Summary

Still can change wishlist URL although wishlist set to private, in conditional, when URL set to private, user can't change wishlist URL, but i found how to change URL although user set wishlist URL to Private

Step To Reproduce : 

1. login to store.line.me
2. go to wishlist -> setting,
3. turn on burp suite -> catch request when change url
4. set wishlist to private again.
5. and replay the request from step 3,

This is not eligibly for bounty, although line side it's say this is bug, but not security bug.


This mean, i need to try learn more and more. hehehe, wish me luck.

Video : https://youtu.be/gyp3T7Cnw5c

Comments

Popular posts from this blog

Open Redirect On Codepolitan.com

Tokopedia - CSRF On Open Store

Missing CSRF Token On Add Admin [Popoji CMS]