cspshivam/playground
Modern Level 1 / 14 Medium
← All labs

Object-Reference Abuse (IDOR)

A billing portal keys invoices by opaque reference and never checks who owns them, while a sibling API quietly lists them. Open an invoice that is not yours.

CSPSHIVAM Billing

Signed in as you. Invoices open by their reference. References are random and unguessable — in this app, that's the only thing standing between you and someone else's invoice.

Your invoices

INV-C9ACA4A0 $120.00
INV-267D2C7A $40.00

View recent account activity →

The Open button submits its invoice reference in a hidden field. Opening an invoice that isn't listed here means changing that reference in the request itself.

This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of CSPSHIVAM Playground is not part of the target.