Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How a GraphQL Bug Resulted in Authentication Bypass

Summary

A researcher abused a GraphQL API with weak access control as an alternate channel to bypass authentication and escalate to admin in an e-commerce app, exposing promo banner and product data.
Published
Collected

original ↗

Related coverage

back