https://samidunimsara.github.io/posts/Exploiting-Unprotected-Functionality/
Exploiting Unprotected Functionality to Access User Profiles - nmsr