Loading HuntDB...

Bypassing Bronze Partner Wallet Restriction to Accept Trips with Negative Balance

Medium
B
Bykea
Submitted None

Team Summary

Official summary from Bykea

@bugbountywithmarco discovered a business logic flaw that allowed Bronze-tier partners with negative wallet balances to bypass platform restrictions and accept trips. By chaining three backend endpoints `GET /v2/:city_id/bookings`, `PUT /api/v2/driver/update/location` (with any trip_id), and `POST /api/v2/offer/bid` a negative balance driver could reset their availability and successfully submit bids, enabling unauthorized access to trips despite wallet limitations.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Business Logic Errors