[Writeup][Bug Bounty][Tokopedia] Manipulation of Likes in Product Reviews [EN]

Before starting, IDOR is Insecure Direct Object Reference, hereinafter referred to as IDOR, is a condition in which users can access an object without passing the access rights check. (OWASP, 2019)

With IDOR, a user can access, change, and delete data. This makes IDOR a very dangerous security hole. Please note, the bug discussed in this writeup has been patched by Tokopedia and screenshots will be censored because of PII.

Affected Endpoint



Manipulation of number of likes in Product Reviews

Steps to Reproduce



Muhammad Thomas Fadhila Yahya

A man who believes in Hogwarts and Wakanda

