Security Finding @Binance Square Official @Daniel Zou (DZ) đ¶
Discovered potential IDOR/information disclosure in Binance Creatorpad leaderboards.
URL pattern:
/creatorpad/{project}global/leaderboard
Simply changing {project} (duskâxplâvanar etc.) reveals different project leaderboards without access control checks.
đ Risk: Unauthorized access, project enumeration, early data exposure.


