pii-disclosure

1 article
sort: new top best
clear filter
0 6/10

A security researcher discovered an IDOR vulnerability in an e-commerce platform where unauthorized access to user account data (name, address, credit card details) could be achieved by exploiting misconfigured CORS that exposed random checkout hashes to third-party integrations, allowing attackers to enumerate and access arbitrary user wallets via predictable endpoints.

Harsh Parekh notmarshmllow
notmarshmllow.medium.com · kh4sh3i/bug-bounty-writeups · 17 hours ago · details