Loading HuntDB...

User can pay using archived price by manipulating the request sent to `POST /v1/payment_pages/for_plink`

Medium
S
Stripe
Submitted None

Team Summary

Official summary from Stripe

@gregxsunday discovered a way to purchase a product with an archived price using a payment link. The bypass was possible because of missing validation. A change was shipped to ensure both the payment link and price are active. Note: This bug was accepted and received before our minimum bounty amounts were increased on August 25, 2021.

Reported by gregxsunday

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)