Back to directory
WRITEUP #1803

Unprotected API endpoint at HAwebsso.nl leads to data leak of +15k medical doctor usernames & password hashes

IDORSSOMissing authentication
by@JonathanBouman(Jonathan Bouman)
Program
HAwebsso.nl
Published
Dec 14, 2022
Added to HackDex
Dec 20, 2022
Read Full Writeuphttps://medium.com/@jonathanbouman/unprotected-api-endpoint-at-hawebsso-nl-5f1951e212fe
RELATED WRITEUPS
Plug Security Holes in React Apps That Can Lead to API Exploitation
Auth BypassSSO
Zomatoooo! IDOR in Saved Payments
IDOR
From MLOps to MLOops: Exposing the Attack Surface of Machine Learning Platforms
AI / LLMAI
How 1 Exposed Honeywell API Gave us Control Over an Internal Engineering System
ReconMissing authentication
Forced SSO Session Fixation
Auth BypassSSO

Built with ❤️ by Shubham Rawat