cors

31 articles
sort: new top best
clear filter
0 6/10

A security researcher discovered an IDOR vulnerability in an e-commerce platform where unauthorized access to user account data (name, address, credit card details) could be achieved by exploiting misconfigured CORS that exposed random checkout hashes to third-party integrations, allowing attackers to enumerate and access arbitrary user wallets via predictable endpoints.

Harsh Parekh notmarshmllow
notmarshmllow.medium.com · kh4sh3i/bug-bounty-writeups · 15 hours ago · details
0
security
blog.bi.tk · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
bugbaba.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
smaranchand.com.np · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
security
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
blog.securitybreached.org · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
blog.takemyhand.xyz · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
bugbaba.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
vulnerability
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
cybristerboy.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
itsecguy.com · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
whitton.io · devanshbatham/Awesome-Bugbounty-Writeups · 15 hours ago · details
0
vikash-vishnoi.medium.com · Vikash Vishnoi · 20 hours ago · details
0
vikash-vishnoi.medium.com · Vikash Vishnoi · 20 hours ago · details
0
medium.com · montaser mohsen · 20 hours ago · details
0
medium.com · montaser mohsen · 20 hours ago · details
0
espiradev.org · aespira · 1 day ago · details · hn
0
satproto.org · remywang · 1 day ago · details · hn
0
codeberg.org · todsacerdoti · 4 days ago · details · hn
more →