Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

The Red Agent POV: Exploiting Broken Object-Level Authorization in an Airline GraphQL API

Summary

Part 2 of the Red Agent POV series: an autonomous BOLA exploit against an airline's GraphQL booking API used sequential IDs to read two years of passenger records and even modify live bookings.
Published
Collected

original ↗

Related coverage

back