credit-card-data-leakage

1 article
sort: new top best
clear filter
0 7/10

A researcher chained improper authorization with a race condition to harvest credit card details from an e-commerce checkout page. By rapidly multi-threading requests to a checkout URL while a victim submitted their payment information, the attacker could receive server responses containing full credit card and personal details before redirect, bypassing the need for form submission errors.

Mandeep Jadon Burp Intruder
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details