webPromedium
Lab 31 — PayStream — IDOR in GraphQL Billing API
hackadvisor
Task: Multi-tenant SaaS billing platform with GraphQL API for invoice management. Solution: Exploited IDOR in InvoiceDetails query to access other tenants' invoices and retrieve flag from hidden internalNotes field.
$ ls tags/ techniques/
idor_exploitationgraphql_introspectiontenant_isolation_bypasshidden_field_discovery
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 251 — PulseBoard — IDOR via Unauthenticated GraphQL User Profile Query— hackadvisor
- [web][Pro]Lab 290 — PayLedger — GraphQL Broken Access Control— hackadvisor
- [web][Pro]Lab 22 — GrubFleet — IDOR in GraphQL Store Management API— hackadvisor
- [web][Pro]Lab 298 — PayLedger — SQL Injection via GraphQL Date Filters— hackadvisor
- [web][Pro]Lab 198 — PayrollSync — Broken Auth via GraphQL Introspection— hackadvisor