Back to directory
WRITEUP #1788

[GraphQL IDOR]Leaking credit card information of 1000s of users

IDORGraphQL
byVipul Sahu
Bounty
1,500
Program
-
Published
Dec 20, 2022
Added to HackDex
Dec 23, 2022
Read Full Writeuphttps://infosecwriteups.com/graphql-idor-leaking-credit-card-information-of-1000s-of-users-d07eec732979
RELATED WRITEUPS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Zomatoooo! IDOR in Saved Payments
IDOR
Authorization bypass due to cache misconfiguration
APIAuthorization bypass
How I got my first $13500 bounty through Parameter Polluting (HPP)
IDORXSS
A Creative Way To Get Someones YouTube Videos Deleted + A Copyright Strike Against Their YouTube Channel
IDORBroken Access Control

Built with ❤️ by Shubham Rawat