Improper handling of payment callback allows topping up a Swiss Starbucks Card bypassing actual payment via a crafted success message

Disclosed: 2019-11-18 22:19:34 By khovansky To starbucks
High
Vulnerability Details
No vulnerability description provided or it is restricted.
Actions
View on HackerOne
Report Stats
  • Report ID: 682617
  • State: Closed
  • Substate: resolved
  • Upvotes: 19
Share this report