How a GraphQL Bug Resulted in Authentication Bypass
hackerone.com | vulnerability | #bug-bounty | #access-control | #authentication-bypass | #privilege-escalation | #api-security | #graphql | #e-commerce
Summary
A researcher abused a GraphQL API with weak access control as an alternate channel to bypass authentication and escalate to admin in an e-commerce app, exposing promo banner and product data.
- Published
- Collected
Skip to content