How I found an IDOR in Google Classroom on Day 3 of my Hunting?
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A beginner bug hunter describes finding an Insecure Direct Object Reference (IDOR) vulnerability in Google Classroom on their third day of hunting. By mapping Google's internal batchexecute RPC system and its rpcids, they discovered that the private comment endpoint on assignment submissions lacked proper authorization checks. Replacing their own submission ID with a victim's submission ID in the request allowed posting comments to another student's private thread without authorization. They also found a separate endpoint leaking all enrolled students' submission IDs, making the attack realistic. The report was submitted to Google VRP but came back as a duplicate.