Back to directory
WRITEUP #6060

GraphQL abuse: Bypass account level permissions through parameter smuggling

APIGraphQLPrivilege escalation
by@jon_bottarini(Jon Bottarini)
Program
New Relic
Published
Mar 14, 2018
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://labs.detectify.com/2018/03/14/graphql-abuse/
RELATED WRITEUPS
Authorization bypass due to cache misconfiguration
APIAuthorization bypass
The Butterfly Effect: Turning Overlooked - Misconfigurations into Zero Click Account Takeover
APIGraphQL
Exploiting Broken Authentication Control In GraphQL
CloudGraphQL
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
Escalating From Reader To Contributor In Azure API Management
Privilege Escalation

Built with ❤️ by Shubham Rawat