InfoSec Write-ups
Read post

How I found an IDOR in Google Classroom on Day 3 of my Hunting?

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A beginner bug hunter describes finding an Insecure Direct Object Reference (IDOR) vulnerability in Google Classroom on their third day of hunting. By mapping Google's internal batchexecute RPC system and its rpcids, they discovered that the private comment endpoint on assignment submissions lacked proper authorization checks. Replacing their own submission ID with a victim's submission ID in the request allowed posting comments to another student's private thread without authorization. They also found a separate endpoint leaking all enrolled students' submission IDs, making the attack realistic. The report was submitted to Google VRP but came back as a duplicate.

    #authorization
Yesterday•4m read time•From infosecwriteups.com
Post cover image
72 Impressions
InfoSec Write-ups's image
InfoSec Write-ups

InfoSecWriteUps' platform is dedicated to providing insights and resources for cybersecurity profes...

977 Followers

•

4.1K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard