HackerOne Disclosed Reports - 2025-11-17

0 Replies, 101 Views

Logo
Critical
resolved

Authentication Bypass in Subscription Management Endpoint


Bug reported by Ahmed was disclosed at November 17, 2025, 1:08 pm   |   Insecure Direct Object Reference (IDOR)

A vulnerability was identified in the subscription management functionality that allowed unauthorized access to customer billing information. The issue stemmed from insufficient authentication and authorization controls on an API endpoint. The vulnerability was classified as an Insecure Direct Object Reference (IDOR) vulnerability, where customer identifiers could be manipulated to access other users' data. The vulnerability has been promptly addressed and fixed by the development team.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)