A disturbing bug Javed said he found was the ability to take over and compromise every website created with Microsoft’s Power Portals—equating to about 1,700 websites, according to Javed. An Insecure Direct Object Reference (IDOR) attack laid the groundwork for Javed to access the web app, he said.
Read full article on Motherboard