The Red Agent POV: Exploiting Broken Object-Level Authorization in an Airline GraphQL API
wiz.io | blog | #data-exposure | #api-security | #graphql | #bola | #authorization-bypass | #red-agent
Summary
Part 2 of the Red Agent POV series: an autonomous BOLA exploit against an airline's GraphQL booking API used sequential IDs to read two years of passenger records and even modify live bookings.
- Published
- Collected
Skip to content