json-manipulation

2 articles
sort: new top best
clear filter
0 3/10

A researcher discovered a two-factor authentication bypass in a private program by removing the VerificationDetails object from a JSON API request, allowing toggling of 2FA without OTP validation. The vulnerability was awarded $50.

Aung Pyae Ko Ko
aungpyaekoko.medium.com · kh4sh3i/bug-bounty-writeups · 3 hours ago · details
0 5/10

Researcher discovered a full account takeover vulnerability by chaining multiple weaknesses: a password change endpoint that accepted null CSRF tokens and lacked proper validation, combined with a hidden 'uid' parameter discoverable via Param Miner that allowed changing arbitrary users' passwords without authentication. The vulnerability earned a $1000 bounty.

Mohsin Khan Param Miner James Kettle PortSwigger Burp Suite
mokhansec.medium.com · kh4sh3i/bug-bounty-writeups · 3 hours ago · details