Source |
IT Security Guru |
Identifiant |
4418172 |
Date de publication |
2022-04-08 14:30:21 (vue: 2022-04-08 15:07:53) |
Titre |
Server-Side-Request-Forgery Enabled Administrative Account Takeover on FinTech Platform |
Texte |
Salt Labs has uncovered a Server-Side-Request Forgery on a major FinTech platform, enabling an administrative account takeover. Researchers identified API vulnerabilities allowing them to launch attacks where: Attackers could gain administrative access to the banking platform Attackers could leak users' personal data Attackers could access users' banking details and financial transactions Attackers could perform unauthorised […]
|
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
access account administrative allowing api attackers attacks banking could data details enabled enabling financial fintech forgery gain has identified labs launch leak major perform personal platform request researchers salt server side takeover them transactions unauthorised uncovered users vulnerabilities where: |
Tags |
|
Stories |
|
Move |
|