3
TOTAL FINDINGS
1
CRITICAL
2
HIGH
3
WRITEUPS
FINDING_001 · SERVER-SIDE HIGH
SSRF

SSRF Vulnerability — Internal Cloud Infrastructure Exposure

Discovered a Server-Side Request Forgery that allowed internal IP probing, metadata endpoint access, and exposure of internal cloud infrastructure through manipulated request parameters.

SSRF Cloud Internal Network Metadata Endpoint
↗ Read Full Write-Up
FINDING_002 · BUSINESS LOGIC HIGH
PRICE MANIPULATION

Price Manipulation / Business Logic Flaw

Identified a price manipulation vulnerability in an e-commerce application where the backend blindly trusted client-side request values, allowing attackers to modify product prices before checkout.

Business Logic Client Trust E-Commerce Parameter Tampering
↗ Read Full Write-Up
FINDING_003 · ACCOUNT TAKEOVER CRITICAL
0-CLICK ATO

Punycode-Based Account Takeover — 0-Click!

Found a Punycode-based vulnerability that can lead to a serious 0-click Account Takeover when applications blindly trust user-controlled input. No interaction from the victim required.

0-Click Account Takeover Punycode Input Validation
↗ Read Full Write-Up