Web Hack List

Other nomination

Authorization bypass due to cache misconfiguration

A short-lived server-side cache on an e-commerce admin GraphQL endpoint stored the order-listing response without including the caller's authorisation in the cache key. This bug bounty write-up shows that a low-privilege user replaying the same operation with a publicly known shop identifier inside the three-to-four second window received the cached administrator response, exposing order and customer data even though the endpoint otherwise returned 403 to that user.

Record

Researcher
Rikesh Baniya
Published by
Medium
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Rikesh Baniya, first published at the original source. Preserved copies are kept so the citation survives its host.