Unrestricted Access to Sensitive Business Flows

circle-info

Unrestricted Access to Sensitive Business Flows occurs when users can access or manipulate sensitive business processes or functionalities without appropriate authorization or access controls.

triangle-exclamation
circle-check

The below example is based on HTB's API Attacksarrow-up-right module.

The endpoint below reveas the products' discount period which can be exploited by a threat actor by making automated purchases on the starting date and reselling them later at a higher price (Figure 1).

Figure 1: An endpoint that exposes a sensitive business flow.

Last updated

Was this helpful?