logo

8 High-impact Bugs and How HackerOne Customers Avoided a Breach: SQL Injection

ID: cf7e547b-7767-57c9-bd8a-ed33c41257a9

STIX ID: report--cf7e547b-7767-57c9-bd8a-ed33c41257a9

Feed Name: HackerOne Blog

Threat Score
70/100

Date Published: 2023-09-22

Date Updated: 2026-06-11

...
...

This HackerOne blog post examines SQL Injection as a high-impact vulnerability, illustrating two real-world disclosures — one against Starbucks and one against the U.S. Department of Defense — where researchers used manual testing and tools like sqlmap to confirm SQLi, leading to rapid triage and remediation (and a bounty in Starbucks’ case). The write-up highlights attack vectors, potential business and national-security impacts, and the value of coordinated disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.