Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Edit/Modify Non-Sensitive Information IDOR should be categorzed as P4 #406

Open
georgedevasia0 opened this issue Feb 16, 2024 · 1 comment

Comments

@georgedevasia0
Copy link

As of now Edit/Modify Non-Sensitive Information IDOR is categorized as P5. Suppose I am editing a cross tenant record where I don't have the access, it is medium critical and it should have a higher severity.

If I'm editing/modifying a iterate Non-Sensitive Information, then the impact is much higher than we imagine. As per the vulnerability rating taxonomy, all IDOR's except Read Non-Sensitive Information should be having minimum priority of P4.

Please try to do immediate changes in the classification.

@TimmyBugcrowd
Copy link
Contributor

Thank you for your participation. We will soon make changes for the IDOR section and I will update you here and get your input as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants