HackerOne disclosed on HackerOne: Insecure Direct Object Reference...

### Hi H1 i hope you are Doing Well Today :) ### Explaining * I Found that any private reports can be accessed by sending a POST request to the `/bugs.json` endpoint. This vulnerable endpoint requires `organization_id`, which takes the organization's ID as a value. It also requires `text_query`…