![]() |
|
HackerOne Disclosed Reports - 2025-03-02 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2025-03-02 (/Thread-HackerOne-Disclosed-Reports-2025-03-02) |
HackerOne disclosed reports - 2025-03-02 - hashXploiter - 03-03-2025
High
resolved Broken Access Control leads to disclosure of transaction history via /v2/rechargeTransactionHistory endpointBug reported by Hafiz Abdulaziz was disclosed at March 2, 2025, 2:56 pm | The /v2/rechargeTransactionHistory endpoint in the MyMTN NG mobile app was vulnerable to unauthorized access, allowing an attacker to retrieve transaction details of other users, including recharge dates, amounts before and after the transaction, and transaction IDs.
Critical
resolved Admin Dashboard Access Leads to Updating Merchant InfoBug reported by Clement 'Tino was disclosed at March 2, 2025, 1:53 pm | Improper Access Control - Generic The hidden registration endpoint allowed an unauthorized user to sign up for the admin portal, granting access to the registered merchant information. The administrative functionalities permitted the modification of merchant financial account details, disabling and deleting of client accounts. |