uncrypt/playground
Modern Level 1 / 14 Medium
← All labs

Object-Reference Abuse (IDOR)

A billing portal keys invoices by opaque reference and never checks who owns them, while a sibling API quietly lists them. Open an invoice that is not yours.

Uncrypt Billing

Signed in as you. Invoices open by their reference. References are random and unguessable — in this app, that's the only thing standing between you and someone else's invoice.

Your invoices

INV-82993715 $120.00
INV-B49B916C $40.00

View recent account activity →

The Open button submits its invoice reference in a hidden field. Opening an invoice that isn't listed here means changing that reference in the request itself.

This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of Uncrypt Playground is not part of the target.