[jedit:bugs] #4147 Found Vulnerability:- IDOR (Insecure Direct Object Reference)
kunal waidande via jEdit-devel <[email protected]> Tue, 16 Sep 2025 13:57:20 -0000
| Newsgroups | gmane.editors.jedit.devel |
|---|---|
| Message-ID | </p/jedit/bugs/4147/915f2e44d6f8fec566c6b4e3b3af2be74e2dcb8d.bugs@jedit.p.sourceforge.net> |
This is a multi-part message in MIME format. --===============2337718012716748581== Content-Type: multipart/related; boundary="===============6755529981360630506==" This is a multi-part message in MIME format. --===============6755529981360630506== Content-Type: multipart/alternative; boundary="===============1722660824422843721==" MIME-Version: 1.0 --===============1722660824422843721== MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit *Before re-testing it first Login your account then only you will see response 200 ok:- In 6th point after modifying the account id from request you will see that response is ok in repeater, it must not happen. If somone modify the account id it must show error code. I have also send the PDF report with POC. --- **[bugs:#4147] Found Vulnerability:- IDOR (Insecure Direct Object Reference)** **Status:** open-invalid **Group:** UNUSED **Labels:** IDOR (Insecure Direct Object Reference) **Created:** Thu Sep 11, 2025 08:58 PM UTC by kunal waidande **Last Updated:** Mon Sep 15, 2025 06:54 PM UTC **Owner:** nobody **Attachments:** - [jedit.org report.pdf](https://sourceforge.net/p/jedit/bugs/4147/attachment/jedit.org%20report.pdf) (920.8 kB; application/pdf) The following API endpoint allows an attacker to change account-id in the query string and receive a valid response tied to that account. Vulnerable endpoint: GET /a/api/fastlane.json?account_id=15680&site_id=103240 How to perform: 1- Go to website (https://www.jedit.org) 2- In home page on right side you will see sourceForge Project option. 3- Open burpsuit and on the intercept and in browser click on sourceForge Project option. 4- Forward the first and second request and then you will see bunch of requests in that request. 5- You that requests you will see (https://fastlane.rubiconproject.com). 6- Send it to repeater and change the account id. 7- You will see that response is 200 OK . Please find attached PDF report in that, I have created all the manually tested proof report. --- Sent from sourceforge.net because [email protected] is subscribed to https://sourceforge.net/p/jedit/bugs/ To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/jedit/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list. --===============1722660824422843721== MIME-Version: 1.0 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: 7bit <div class="markdown_content"><p>*Before re-testing it first Login your account then only you will see response 200 ok:-</p> <p>In 6th point after modifying the account id from request you will see that response is ok in repeater, it must not happen. If somone modify the account id it must show error code. I have also send the PDF report with POC.</p> <hr/> <p><strong><a class="alink" href="https://sourceforge.net/p/jedit/bugs/4147/">[bugs:#4147]</a> Found Vulnerability:- IDOR (Insecure Direct Object Reference)</strong></p> <p><strong>Status:</strong> open-invalid<br/> <strong>Group:</strong> UNUSED<br/> <strong>Labels:</strong> IDOR (Insecure Direct Object Reference) <br/> <strong>Created:</strong> Thu Sep 11, 2025 08:58 PM UTC by kunal waidande <br/> <strong>Last Updated:</strong> Mon Sep 15, 2025 06:54 PM UTC<br/> <strong>Owner:</strong> nobody<br/> <strong>Attachments:</strong></p> <ul> <li><a class="" href="https://sourceforge.net/p/jedit/bugs/4147/attachment/jedit.org%20report.pdf">jedit.org report.pdf</a> (920.8 kB; application/pdf)</li> </ul> <p>The following API endpoint allows an attacker to change account-id in the query string and receive a valid response tied to that account.</p> <p>Vulnerable endpoint: GET /a/api/fastlane.json?account_id=15680&site_id=103240</p> <p>How to perform:<br/> 1- Go to website (https://www.jedit.org)<br/> 2- In home page on right side you will see sourceForge Project option.<br/> 3- Open burpsuit and on the intercept and in browser click on sourceForge Project option.<br/> 4- Forward the first and second request and then you will see bunch of requests in that request.<br/> 5- You that requests you will see (https://fastlane.rubiconproject.com).<br/> 6- Send it to repeater and change the account id.<br/> 7- You will see that response is 200 OK .</p> <p>Please find attached PDF report in that, I have created all the manually tested proof report.</p> <hr/> <p>Sent from sourceforge.net because [email protected] is subscribed to <a href="https://sourceforge.net/p/jedit/bugs/">https://sourceforge.net/p/jedit/bugs/</a></p> <p>To unsubscribe from further messages, a project admin can change settings at <a href="https://sourceforge.net/p/jedit/admin/bugs/options.">https://sourceforge.net/p/jedit/admin/bugs/options.</a> Or, if this is a mailing list, you can unsubscribe from the mailing list.</p></div> --===============1722660824422843721==-- --===============6755529981360630506==-- --===============2337718012716748581== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============2337718012716748581== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- ----------------------------------------------- jEdit Developers' List [email protected] https://lists.sourceforge.net/lists/listinfo/jedit-devel --===============2337718012716748581==--