*Before re-testing it first Login your account then only you will see response 200 ok:- In 6th point after modifying the account id from request you will see that response is ok in repeater, it must not happen. If somone modify the account id it must show error code. I have also send the PDF report with POC.
Found Vulnerability:- IDOR (Insecure Direct Object Reference)
Found Vulnerability:- IDOR (Insecure Direct Object Reference)