Back to directory
WRITEUP #4315

6k$ Worth Account Takeover via IDOR in Starbucks Singapore

IDORAccount takeover
by@ko2sec(Kamil Onur Özkaleli)
Bounty
6,000
Program
Starbucks
Published
Oct 7, 2020
Added to HackDex
Sep 15, 2022
Read Full Writeuphttp://www.kamilonurozkaleli.com/posts/starbucks-singapore-account-takeover/
RELATED WRITEUPS
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover
Self-XSS to ATO via Site Features
XSSSelf-XSS
Zomatoooo! IDOR in Saved Payments
IDOR
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover

Built with ❤️ by Shubham Rawat