SQL Injection Extracts Starbucks Enterprise Accounting, Financial, Payroll Database
Critical
S
Starbucks
Submitted None
Team Summary
Official summary from Starbucks
As described in the Hacker Summary, @spaceraccoon discovered a SQL Injection vulnerability in a web service backed by Microsoft Dynamics AX. @spaceraccoon demonstrated that the flaw was exploitable via XML-formatted HTTP payload requests to the server. We appreciate @spaceraccoon's clear and thorough report, which helped us quickly and effectively triage the report and remediate the vulnerability.
Actions:
Reported by
spaceraccoon
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
SQL Injection