Loading HuntDB...

SQL Injection Extracts Starbucks Enterprise Accounting, Financial, Payroll Database

Critical
S
Starbucks
Submitted None

Team Summary

Official summary from Starbucks

As described in the Hacker Summary, @spaceraccoon discovered a SQL Injection vulnerability in a web service backed by Microsoft Dynamics AX. @spaceraccoon demonstrated that the flaw was exploitable via XML-formatted HTTP payload requests to the server. We appreciate @spaceraccoon's clear and thorough report, which helped us quickly and effectively triage the report and remediate the vulnerability.

Reported by spaceraccoon

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

SQL Injection