How an Improper Access Control Vulnerability Led to Account Theft in One Click
ID: f4f5c1d2-4618-5d7b-8991-0a1887e7267e
STIX ID: report--f4f5c1d2-4618-5d7b-8991-0a1887e7267e
Feed Name: HackerOne Blog
Threat Score
This HackerOne report explains improper access control risks, business impacts, and remediation guidance, and highlights a critical real-world example where a malicious deeplink in the KAYAK Android app allowed an unauthenticated attacker to steal session cookies and perform one-click account takeover; KAYAK issued a patch via Google Play the next day.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
