Shipt | Report #1903322 - Improper Access Control + Financial fraud allows attacker to disclose + add arbitrary products to another's user's order | HackerOne

https://hackerone.com/reports/1903322