Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on sh.itjust.works
cybersecurity·Cybersecuritybyborari

Compromising Honda’s power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API

The researcher chained an insecure password reset API route to bypass authentication, then discovered an IDOR vulnerability could be leveraged to access sensitive customer data.

For everyone that says "The real world can't be as easy as training labs make it seem out to be!", sometime it really do be that ez.

Compromising Honda’s power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset APIhttps://eaton-works.com/2023/06/06/honda-ecommerce-hackOpen linkView original on sh.itjust.works
5

1 reply

You reached the end

Compromising Honda’s power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API | Spyke