Web Hack List

Collected research

Authorization bypass due to cache misconfiguration

A short-lived server-side cache on an e-commerce admin GraphQL endpoint stored the order-listing response without including the caller's authorisation in the cache key. This bug bounty write-up shows that a low-privilege user replaying the same operation with a publicly known shop identifier inside the three-to-four second window received the cached administrator response, exposing order and customer data even though the endpoint otherwise returned 403 to that user.

Record

Researcher
Rikesh Baniya
Published by
Medium
Date
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Rikesh Baniya, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .