Loading HuntDB...

Unrestricted File Upload Leads to RCE on mobile.starbucks.com.sg

Critical
S
Starbucks
Submitted None

Team Summary

Official summary from Starbucks

ko2sec discovered an .ashx endpoint on mobile.starbucks.com.sg intended for image files permitted unrestricted file type uploads which could lead to a potential RCE. ko2sec's thorough analysis provided additional endpoints on other out of scope domains that shared this vulnerability. @ko2sec — thank you for reporting this vulnerability and for confirming the resolution.

Reported by ko2sec

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic