HackerOne Bug Bounty Disclosure: idor-account-deletion-via-session-misbinding-attacker-can-delete-victim-account-z-phyrus
Company Name:
Mozilla
Company HackerOne URL:
https://hackerone.com/mozilla
Submitted By:
z3phyrus
Link to Submitters Profile:
https://hackerone.com/z3phyrus
Report Title:
IDOR: Account Deletion via Session Misbinding Attacker Can Delete Victim Account
Report Link:
https://hackerone.com/reports/3154983
Date Submitted:
03 June 2025
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.