improper-authorization

2 articles
sort: new top best
clear filter
0 7/10

A researcher discovered an improper authorization vulnerability combined with a race condition on an e-commerce checkout page that allowed attackers to harvest credit card details by rapidly requesting a checkout URL with Burp Intruder while a victim submitted payment information, causing the server to leak cached form data before redirecting.

Mandeep Jadon Burp Intruder
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 8 hours ago · details
0 7/10
vulnerability

A researcher discovered an improper authorization vulnerability in HackerOne's embedded submission form feature that allows bypassing both the 2FA requirement enforcement and program-level hacker blacklists by submitting reports through the embedded submission URL instead of the standard interface.

HackerOne Japz Divino Parrot Security Ace Candelario Jobert (HackerOne Co-Founder)
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 8 hours ago · details