← All series

Ottergram

Daily · 9 writeups

A recurring daily challenge — each entry covers a different vulnerability. Listed oldest to newest.

BugForge - Daily - Ottergram (Jan 3, 2026)

A SQL Injection vulnerability was identified in the user profile retrieval functionality where user-supplied input is concatenated directly into SQL…

SQLi
Posted on 2026-01-03 20:00 4 min read
BugForge - Daily - Ottergram

BugForge - Daily - Ottergram (Jan 10, 2026)

The application exposes a GraphQL API with introspection enabled in production, allowing attackers to query the full API schema and discover sensitive…

Graphql Introspection IDOR Broken Access Control
Posted on 2026-01-10 20:00 5 min read
BugForge - Daily - Ottergram

BugForge - Daily - Ottergram (Jan 17, 2026)

This walkthrough demonstrates how an Insecure Direct Object Reference (IDOR) can surface in real-time features by moving beyond basic HTTP endpoints and…

Web Sockets IDOR
Posted on 2026-01-17 19:25 3 min read
BugForge - Daily - Ottergram

BugForge - Daily - Ottergram (Jan 24, 2026)

A stored Cross-Site Scripting (XSS) vulnerability was identified in the messaging functionality where user input is rendered using React's…

XSS Oob
Posted on 2026-01-24 20:00 4 min read
BugForge - Daily - Ottergram

BugForge - Daily - Ottergram (Jan 31, 2026)

The Ottergram application contains an Insecure Direct Object Reference (IDOR) vulnerability in its profile update functionality. While the application…

IDOR Broken Access Control
Posted on 2026-01-31 20:00 4 min read
BugForge - Daily - Ottergram

BugForge - Daily - Ottergram (Feb 7, 2026)

The Ottergram application contains a Missing Function Level Access Control vulnerability in its administrative post deletion endpoint. The application…

Broken Access Control Missing Function Level Access Control
Posted on 2026-02-07 19:00 4 min read
BugForge - Daily - Ottergram

BugForge - Daily - Ottergram (Feb 14, 2026)

The Ottergram application contains a Broken Access Control vulnerability in its comment update endpoint. After systematically analyzing the application's…

Broken Access Control Missing Authentication
Posted on 2026-02-14 19:00 4 min read
BugForge - Daily - Ottergram

BugForge - Daily - Ottergram (Feb 21, 2026)

The Ottergram application contains a Path Traversal vulnerability in its post image serving endpoint. After exploring the application's main feed and user…

File Inclusion Path Traversal
Posted on 2026-02-21 19:00 5 min read
BugForge - Daily - Ottergram

BugForge - Daily - Ottergram (Feb 28, 2026)

The Ottergram application contains an HTTP Verb Tampering vulnerability combined with an Insecure Direct Object Reference (IDOR) flaw in its comment…

Broken Access Control IDOR Http Verb Tampering
Posted on 2026-02-28 19:00 5 min read
BugForge - Daily - Ottergram
Zw4rts

© 2026 Zw4rts. All rights reserved.

GitHub