WhisperX tag archive

#BOLA/IDOR

This page collects WhisperX intelligence signals tagged #BOLA/IDOR. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-21 11:22:48 · GitHub Issues

1. Stripe Sandbox API Anomaly: Authenticated Users Blocked from Accessing Their Own Customer Records

A critical access control anomaly has been identified in Stripe's sandbox environment, where authenticated users are being blocked from retrieving their own customer data. During a penetration test, a call to the `GET /v1/customers/{id}` endpoint with a valid customer ID belonging to the authenticated account returned ...