Summary
The invoice export endpoint checked that a caller was authenticated, but never checked that they belonged to the account they were exporting. An authenticated user on any tenant could pull another organisation's invoices by changing a single identifier.
Proof of concept
- Sign in as a low-privilege user belonging to tenant A.
- Trigger an invoice export and capture the request.
- Change
account_idfrom A's identifier to tenant B's. - Replay. The response returns tenant B's invoices as a PDF.
GET /api/v2/accounts/8f21c4/invoices/export.pdf HTTP/2
Host: app.example.com
Authorization: Bearer <tenant A token>
// swapped to tenant B — no membership check runs
GET /api/v2/accounts/1d90be/invoices/export.pdf HTTP/2
→ 200 OK application/pdf 412 KB
Impact
Cross-tenant disclosure of billing records: invoice line items, billing contacts, trading addresses and VAT numbers. Because exports are generated on demand, an attacker could enumerate identifiers and pull the full billing history of every organisation on the platform.
No user interaction is required beyond a valid low-privilege session, and nothing in the response indicates the data belongs to someone else - which is what makes it easy to miss in review and hard to spot in logs.
Example report - redacted and simplified for illustration. Findings are always reported privately to vendors first.
001 Field notes
Recent research.
[Chromium] Drag and drop a Data URI to spoof a dialog
Back in June, I came across some interesting behaviour with Google Chrome. If you drag and drop a Data URI (image or hyperlink) into a new tab and this…
[Outlook] How an attacker could modify your sent items!
In the world of business disputes, the "Sent Items" folder is often treated as the source of truth. We implicitly trust that what sits in that folder is an…
Crafting Malicious Facebook Ads via Instant Experiences
Everyone who uses Facebook has seen them: slick, fast-loading ads that open up into a full-screen experience without ever leaving the app. These are called…
Bypass client-side validation on a Facebook Page Contact Form
The "Action Button" feature found against a Facebook page has an option to create a Contact Form. This Contact Form allows a page to collect pre-defined…
XSS to RCE - Xbox Device Portal
The Xbox Device Portal is an invaluable tool for developers, offering remote access to an Xbox console in developer mode via a web browser. It allows for…
002 Engagements
Put an attacker on your side of the table.
Straight answers, thorough writeups, no theatre. Whether it's a one-off assessment or a standing relationship, you get findings you can act on the same week.
- Web application pentesting
- REST & GraphQL APIs
- Android analysis
- AI safety & security
- Bug bounty
- Live hacking