endpoint-testing

1 article
sort: new top best
clear filter
0 3/10
bug-bounty

A researcher discovered a SQL injection vulnerability in a private HackerOne program through basic parameter fuzzing on a REST endpoint, receiving a $50 bounty. The vulnerability was confirmed by appending a single quote to an id parameter, triggering a MySQL syntax error that revealed the underlying SQL query.

Sunil Yedla Hackerone
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details