payment-bypass

2 articles
sort: new top best
clear filter
0 6/10

A bug bounty writeup describing the exploitation of a race condition combined with business logic flaws in a payment application to bypass deposit minimums and credit balance without valid bank transactions. The attacker leveraged concurrent requests with stolen/reused tokens to exploit a time-of-check-time-of-use vulnerability where the server failed to synchronize balance and minimum deposit validation across threads.

HackerOne Oleksandr Opanasiuk aaronhnatiw/race-the-web
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 16 hours ago · details
0 2/10

A bug bounty hunter discovered a payment bypass vulnerability in a premium course platform that allowed obtaining access for $0 through a business logic flaw, but reports a duplicate submission outcome.

medium.com · El Professor Qais · 2 days ago · details