$1000 Bounty | Business Logic Flaw | Poc Bug bounty

Описание к видео $1000 Bounty | Business Logic Flaw | Poc Bug bounty

While testing your android application I've found a business logic flaw by using which a non premium user can update/change the retailers when ever and what ever retailers he wants to.
Curve application has a functionality called "Earn curve cash". A non premium user can select only 3 retailers (where as premium user can select 6 or more retailers) at a time. A business logic flaw exists at this endpoint by using which a non premium user can update/change already existing retailers and can use cashback with all the retailers associated with curve application.

Комментарии

Информация по комментариям в разработке