Vulnerability Summary
HackerOne disclosed report --> https://hackerone.com/reports/3507241 by aszx87410
The Starknet Snap by Consensys contains a critical security vulnerability that allows malicious websites to bypass user authorization when signing messages or transactions. The vulnerability exists in the enableAuthorize parameter which can be controlled by any website. When set to false, the confirmation dialog is not shown to the user, allowing a malicious website to sign arbitrary messages or transactions without user approval, potentially leading to asset theft.
The bug was a Business Logic vulnerability that allowed users to access paid features while they were on a free plan.
HackerOne disclosed report --> https://hackerone.com/reports/3591764 by ziadmomen
This writeup documents a critical Business Logic Error (CWE-840) discovered in the payment flow of an event-driven e-commerce platform.
No comments yet.
Be the first to share your thoughts
Log in to join the discussion.
Sign In