Pentesting12 min read
We skipped a startup's paid subscription by changing one field in SupabaseNos salteamos la suscripción paga de una startup tocando un solo campo en Supabase
During an authorized pentest we found an authorization flaw: a regular account could change the attribute that defined its privileges and reach internal functions.Durante un pentest autorizado encontramos un fallo de autorización: una cuenta común podía modificar el atributo que definía sus privilegios y acceder a funciones internas.