Back to directory
WRITEUP #1518

Insufficient GraphQL API vulnerability due to lack of validation of Authorization Bearer token

APIGraphQLIDOR
by@intlulz(Int)
Bounty
700
Program
-
Published
Feb 22, 2023
Added to HackDex
Feb 28, 2023
Read Full Writeuphttps://0x1int.gitbook.io/blogs/insufficient-graphql-api-vulnerability-due-to-lack-of-validation-of-authorization-bearer-token
RELATED WRITEUPS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Authorization bypass due to cache misconfiguration
APIAuthorization bypass
Zomatoooo! IDOR in Saved Payments
IDOR
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel
IDORBroken Access Control

Built with ❤️ by Shubham Rawat