Hacker Used Claude AI to Score Free Tickets to Nearly Every US Music Show
ID: 69d4e5ba-188c-5c6a-a213-e03a8f5a014e
STIX ID: report--69d4e5ba-188c-5c6a-a213-e03a8f5a014e
Feed Name: cybersecurityNews.com
A security researcher discovered an unauthenticated SQL injection in Front Gate Tickets' fgtapi frontend that, when abused, allowed full administrative takeover of the ticketing platform used by major US festivals. The endpoint required a deviceUID parameter that was concatenated into raw SQL; a single quote caused a hang, confirming injection. Conventional tools failed due to an AWS WAF, but an AI model (Anthropic Claude) found a payload nesting technique to bypass the WAF and build a blind boolean oracle, enabling extraction of sensitive tables (user credentials, reset and API tokens) and hijacking administrator accounts. The researcher demonstrated control without bulk exfiltration; the vendor reportedly patched the flaw and plans to offer a bug bounty.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
